Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Mattermost Public Bug Bounty Engagement
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Mattermost Public Bug Bounty Engagement? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.

Mattermost is the leading collaboration platform for mission-critical work. We serve national security, government, and critical infrastructure enterprises, from the U.S. Department of Defense, to global tech giants, to utilities, banks and other vital services. We accelerate out-of-band incident response, DevSecOps workflows, mission operations, and self-sovereign collaboration to bolster the focus, adaptability, and resilience of the world’s most important organizations. Our enterprise software and single-tenant SaaS platforms are built to meet the custom needs of rigorous and complex environments while offering a secure and unrivaled collaboration experience across web, desktop, and mobile with channel-based messaging, file sharing, audio calling, and screen share with integrated tooling, workflow automation, and AI assistance. No technology is perfect, and Mattermost believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck and happy hunting! Ratings/Rewards For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.

Currency
USD
Submissions
Open
Scope entries
23 Bugcrowd’s count

Scope

23 assets
AssetTypeEligibilityMax severity
https://bugcrowd-*your-own-instance*.cloud.mattermost.com/ website ✓ bounty not set
Mattermost Boards Plugin other ✓ bounty not set
Mattermost Calls Plugin other ✓ bounty not set
Mattermost Confluence Plugin other ✓ bounty not set
Mattermost Copilot Plugin other ✓ bounty not set
Show all 23 assets
AssetTypeEligibilityMax severity
Mattermost Desktop Apps other ✓ bounty not set
Mattermost Github Plugin other ✓ bounty not set
Mattermost Gitlab Plugin other ✓ bounty not set
Mattermost Jira Plugin other ✓ bounty not set
Mattermost Microsoft Calendar Plugin other ✓ bounty not set
Mattermost Mobile Android android ✓ bounty not set
Mattermost Mobile iOS ios ✓ bounty not set
Mattermost MSTeams Plugin other ✓ bounty not set
Mattermost Playbooks Plugin other ✓ bounty not set
Mattermost Plugin for Microsoft Teams Meetings other ✓ bounty not set
Mattermost Zoom Plugin other ✓ bounty not set
about.mattermost.com website out not set
academy.mattermost.com website out not set
developers.mattermost.com website out not set
docs.mattermost.com website out not set
forum.mattermost.com website out not set
integrations.mattermost.com website out not set
mattermost.com (the main website) website out not set