docs/main/product-overview/mattermost-v10-changelog.mdx
import Inc0_common_esr_support_upgrade from './common-esr-support-upgrade.mdx';
<Inc0_common_esr_support_upgrade />
<Note>Platform and OS scope reflects reported and tested environments and may not represent all affected configurations.
</Note>10.12.4, released 2025-11-21
Critical Fixes
Mattermost v10.12.4 contains a Critical severity level security fix in the Jira plugin. Upgrading to this release as soon as possible is highly recommended. Details will be posted on our security updates page 30 days after release as per the Mattermost Responsible Disclosure Policy.
Pre-packaged Jira plugin version v4.4.1.
Mattermost v10.12.4 contains no database or functional changes.
10.12.3, released 2025-11-17
10.12.2, released 2025-10-28
Critical Fixes
Mattermost v10.12.2 contains Critical severity level security fixes. Upgrading to this release as soon as possible is highly recommended. Details will be posted on our security updates page 30 days after release as per the Mattermost Responsible Disclosure Policy.
Pre-packaged Boards plugin v9.1.7.
Mattermost v10.12.2 contains no database or functional changes.
10.12.1, released 2025-10-15
10.12.0, released 2025-09-16
If you upgrade from a release earlier than v10.10, please read the other Important Upgrade Notes.
UpdatePost.v1.24.6.Known Issue
Customers should not upgrade from >=10.11.17 to <=11.7.2 due to a bug that causes an issue with database migration numbers. The bug is fixed in v11.7.3.
10.11.21, released 2026-06-26
FileSettings.ExtractContentTimeout setting (default 10 seconds) that limits how long a single uploaded document's content extraction occupies a worker, and moved document content extraction to a dedicated, non-blocking worker pool so it no longer delays file uploads for other users. Added FileSettings.ExtractContentTimeout configuration setting.threadmemberships rows where the user is no longer a channel member; irreversible data-only migration that may run slowly on large instances.10.11.20, released 2026-06-12
10.11.19, released 2026-05-27
Edit Attachments for controlling who can edit post attachments when editing a post. By default the permission is granted to whoever has edit post permission.10.11.18, released 2026-05-21
/api/v4/users/{user_id}/demote now returns 400 when user_id is a bot account; bot accounts cannot be converted to guests.10.11.16 / 10.11.17, released 2026-05-13
role_updated WebSocket events to the affected team/channel instead of broadcasting globally. No database downtime is expected for this upgrade. See the Important Upgrade Notes for more details.10.11.15, released 2026-04-22
10.11.14, released 2026-04-15
RefreshedToken that matched the original invite token, preventing proper token rotation.10.11.13, released 2026-03-16
10.11.12, released 2026-02-23
10.11.11, released 2026-02-13
Breaking Changes
Photoshop Document (PSD) files are now no longer inline previewed, they are treated as regular file attachments.
Mattermost v10.11.11 contains low to high severity level security fixes. Upgrading to this release is recommended. Details will be posted on our security updates page 30 days after release as per the Mattermost Responsible Disclosure Policy.
Pre-packaged Boards plugin version v9.2.2.
Fixed an issue where the channel URL got updated when the channel display name was changed.
Added audit logs for when admins access posts on channels they are not a member of.
Fixed a performance regression that caused the requests to populate the Recent mentions right-hand side (RHS) to timeout. This, in turn, re-introduces a known bug in searches with quoted strings, that may include results not exactly matching the quoted string (reported on web and desktop clients and all server systems).
Fixed an issue with PSD file previews.
Added a new MM_LOG_PATH environment variable to restrict log file locations. Log files must now be within a configured root directory.
Fixed an issue where the /mute slash command could be used to enumerate private channels.
Fixed an issue with permalink preview information after losing channel or team permissions.
User's actual authentication method is now validated before processing authentication type switch.
Fixed an issue where users removed from a private team could still enumerate public channels in that team via the channel search API.
Fixed an issue with permalink embeds arriving from websocket messages.
Fixed a memory allocation issue by updating mscfb and msoleps dependencies.
/api/v4/access_control_policies/{policy_id}/activate has been deprecated.
Fixed an issue with memory use during integration actions.
Updated the POST /api/v4/teams team creation API to omit the invite_id value in the response when the requesting user does not have permission to invite members to the new team.
ImportSettings.Directory can no longer be modified through the REST API. Infrastructure operators can still modify this setting via configuration file, environment variables, or mmctl in local mode.
Fixed a permission validation issue when attaching files to posts.
Mattermost v10.11.11 contains no database or functional changes.
10.11.10, released 2026-01-15
10.11.9, released 2025-12-17
Shift+Up in the channel textbox to reply to a thread could cause the right‑hand sidebar (RHS) reply textbox to not focus.10.11.8, released 2025-11-21
Critical Fixes
Mattermost v10.11.8 contains a Critical severity level security fix in the Jira plugin. Upgrading to this release as soon as possible is highly recommended. Details will be posted on our security updates page 30 days after release as per the Mattermost Responsible Disclosure Policy.
Pre-packaged Jira plugin version v4.4.1.
Mattermost v10.11.8 contains no database or functional changes.
10.11.7, released 2025-11-17
10.11.6, released 2025-11-04
10.11.5, released 2025-10-28
Critical Fixes
Mattermost v10.11.5 contains Critical severity level security fixes. Upgrading to this release as soon as possible is highly recommended. Details will be posted on our security updates page 30 days after release as per the Mattermost Responsible Disclosure Policy.
Pre-packaged Boards plugin v9.1.7.
Mattermost v10.11.5 contains no database or functional changes.
10.11.4, released 2025-10-15
10.11.3, released 2025-09-16
10.11.2, released 2025-08-22
10.11.1, released 2025-08-15
10.11.0, released 2025-08-15
If you upgrade from a release earlier than v10.10, please read the other Important Upgrade Notes.
AuditSettings by default.required, and replaced Create Team input with an Input component.AuthData to mmctl user search output.compliance export list command.compliance export show and cancel commands.compliance export download command.compliance export create command.header.mmctl ldap job show without the required argument.in: filter not showing an autocomplete on small screens.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
ServiceSettings in config.json:
DeleteAccountLink configuration setting to add a configurable account deletion link.ClusterSettings in config.json:
EnableGossipEncryption to replace EnableExperimentalGossipEncryption to transition Gossip Encryption functionality to Generally Available. For new installations, the setting will now default to on. Any existing values will still be preserved.ContentFlaggingSettings configuration section.NativeAppSettings in config.json:
MobileEnableSecureFilePreview and MobileAllowPdfLinkNavigation available on Enterprise Advanced to further lock down files on mobile.AccessControlSettings in config.json:
EnableUserManagedAttributes configuration setting to allow using user-editable attributes. These attributes are not allowed by default.v1.24.6.DefaultCategoryName to the Channels table. This is nullable and stores a category name to be added/created when new users join a channel. This is only used if the ExperimentalChannelCategorySetting is enabled. No database downtime is expected for this upgrade. See the Important Upgrade Notes for more details.RemoteId and ChannelId to the PostAcknowledgements table. No database downtime is expected for this upgrade. See the Important Upgrade Notes for more details.LastMembersSyncAt to the SharedChannelRemotes table and added LastMembershipSyncAt to SharedChannelUsers. No database downtime is expected for this upgrade. See the Important Upgrade Notes for more details.LastGlobalUserSyncAt to the RemoteClusters table. No database downtime is expected for this upgrade. See the Important Upgrade Notes for more details.If you upgrade from a release earlier than v10.9, please read the other Important Upgrade Notes.
from: search filter in cross-team searches.EnableSharedChannelsPlugins to re-enable them if needed.EnableSharedChannelsMemberSync and EnableSyncAllUsersForRemoteCluster for Connected Workspaces.ExtraUsers field for exact control over allowed overages.MESSAGES badge appeared in the search bar after clearing text and closing the search box.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
ExperimentalSettings in config.json:
ExperimentalChannelCategorySorting configuration setting to add the ability to automatically sort channels into categories upon creation/renaming.DataRetentionSettings in config.json:
PreservePinnedPosts configuration setting. If it's set to true, pinned posts will not be deleted by data retention.ConnectedWorkspacesSettings in config.json:
MemberSyncBatchSize, SyncUsersOnConnectionOpen, GlobalUserSyncBatchSize configuration settings to allow remote users to be discoverable in the Direct/Group Message modal.mholt/archives and removed code.sajari.com/docconv from https://github.com/mattermost/mattermost.v1.24.3.CategoryId column in SidebarChannels table was added to improve query performance. No database downtime is expected for this upgrade. See the Important Upgrade Notes for more details.AttributeView) was added that aggregates user attributes into a separate table. No database downtime is expected for this upgrade. See the Important Upgrade Notes for more details.SamlSettings.EnableSyncWithLdap is enabled, Mattermost will now check if a user exists on the connected LDAP server during login. If the user doesn't exist on the LDAP server, login will fail. Previously, users not present on the LDAP server could login, but would be deactivated on the next LDAP sync.If you upgrade from a release earlier than v10.8, please read the other Important Upgrade Notes.
[[email protected]](mailto:[email protected])). Although these comply with RFC 5322 and RFC 6532 standards, they introduce unnecessary complexity. If a user already has such an email in your installation, they may face issues like being unable to update their profile. To resolve this, the email must be modified manually using the command: mmctl user email "[[email protected]](mailto:[email protected])" [email protected].true by default.SidebarCategories and SidebarChannels tables.icon_emoji property not working for webhook posts.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
SupportSettings in config.json:
ReportAProblemType, ReportAProblemMail, AllowDownloadLogs configuration settings to enhance the behavior for reporting issues in the platform.ExperimentalAuditSettings in config.json:
Certificate configuration setting to accept a certificate to be used for audit logging egress.LdapSettings in config.json:
ReAddRemovedMembers configuration setting to add a LDAP setting to re-add removed members.monaco-editor and monaco-editor-webpack-plugin, and removed dynamic-virtualized-list, popper.js, react-hot-loader, react-popper from https://github.com/mattermost/mattermost.v1.23.7.icon_emoji property was not working for webhook posts.golang.org/x/net version to v0.39.0.AccessControlPolicies and AccessControlPolicyHistory will be created. The migration is fully backwards-compatible, non-locking, and zero downtime is expected.If you upgrade from a release earlier than v10.7, please read the other Important Upgrade Notes.
EnableLocalMode is now automatically enabled during development.EnableCrossTeamSearch configuration option for cross-team search feature.GET /groups endpoint documentation.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
AccessControlSettings in config.json:
EnableAttributeBasedAccessControl and EnableChannelScopeAccessControl configuration settings.ServiceSettings in config.json:
EnableCrossTeamSearch configuration option for cross-team search feature.ElasticsearchSettings in config.json:
GlobalSearchPrefix which can be used to search across multiple indices having a common prefix. This is useful in a scenario with multiple Elasticsearch instances, where multiple instances are writing to different indices with different prefixes using the ElasticsearchSettings.IndexPrefix setting.bep/imagemeta and removed rwcarlsen/goexif from https://github.com/mattermost/mattermost.v1.23.7.icon_emoji property does not work for webhook posts.BannerInfo in the Channels table for storing metadata for an upcoming licensed feature.If you upgrade from a release earlier than v10.6, please read the other Important Upgrade Notes.
MMEMBED cookie is set.marked package which includes full-width punctuation intervals for Unicode characters fix.teams.microsoft.com is no longer added automatically to the frame ancestors list.include_removed_members option.react-select from v3.0.3 to v5.9.0.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
MetricsSettings in config.json:
ClientSideUserIds where users can set the user IDs that they want to track for client-side webapp metrics. The total number of userIDs have been capped to 5 for performance reasons, otherwise Prometheus gets overwhelmed with high label cardinality. We recommend modifying this list infrequently to ensure Prometheus performance.CacheSettings in config.json:
RedisCachePrefix has been added which can be used to add a prefix to all Redis cache keys.ServiceSettings in config.json:
FrameAncestors to allow frame ancestor domains to be specified when embedding Mattermost in other web sites.NativeAppSettings in config.json:
MobileEnableBiometrics (default: false), MobilePreventScreenCapture (default: false), MobileJailbreakProtection (default: false).LdapSettingsDefaultMaximumLoginAttempts.pluginapi methods for managing groups, a new group source type called GroupSourcePluginPrefix and added a new URL parameter called include_syncable_sources to GET /api/v4/groups.Client4.createPostEphemeral method.v1.22.6.Embedding which allows frame ancestor domains to be specified when embedding Mattermost in other web sites. Note, teams.microsoft.com is no longer added automatically to the frame ancestors list. Added a new configuration setting FrameAncestors.MaxUsersForStatistics configuration setting now only disables the User counts with posts chart, while all other stats remain unaffected. The other stats remain unaffected because that configuration value is no longer needed to disable the other queries since they are always fast now. Post and file counts update daily, so they may not always reflect real-time data. Advanced stats, such as line charts and plugin data, are now hidden until clicked, reducing load time. No performance improvements apply to MySQL since it's scheduled for full deprecation in v11. We recommend migrating to PostgreSQL for better performance and long-term support. Migration times: On a system with 12M posts, and 1M fileinfo entries, the migration takes 15s, but could take several minutes depending on the server's table sizes and database specs. This migration is non-locking. Note that there is no migration for MySQL deployments because this optimization is only applicable for PostgreSQL. See the Important Upgrade Notes for more details.If you upgrade from a release earlier than v10.5, please read the other Important Upgrade Notes.
elasticsearch channel index is out of date.DoActionRequest POST requests was missing.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
ServiceSettings in conig.json:
EnableWebHubChannelIteration was added, which allows a user to control the performance of websocket broadcasting. By default, this setting is turned off. If it is turned on, it improves the websocket broadcasting performance at the expense of poor performance when users join/leave a channel. We don't recommended turning this on unless you have at least 200,000 concurrent users actively using Mattermost.EnableOpenTracing to remove the unused opentracing support.SearchPosts API.metrics tag to client_perf endpoint.v1.22.6.10.5.14, released 2025-10-30
10.5.13, released 2025-10-28
Critical Fixes
Mattermost v10.5.13 contains Critical severity level security fixes. Upgrading to this release as soon as possible is highly recommended. Details will be posted on our security updates page 30 days after release as per the Mattermost Responsible Disclosure Policy.
Pre-packaged Boards plugin v9.1.7.
Mattermost v10.5.13 contains no database or functional changes.
10.5.12, released 2025-10-15
10.5.11, released 2025-09-10
10.5.10, released 2025-08-15
10.5.9, released 2025-07-22
10.5.8, released 2025-06-18
10.5.7, released 2025-05-27
SidebarCategories and SidebarChannels tables.10.5.6, released 2025-05-21
10.5.5, released 2025-05-09
CategoryId column in SidebarChannels table was added to improve query performance. No database downtime is expected for this upgrade. It takes around 2s to add the index on a table with 1.2M rows for PostgreSQL, and it takes around 5s on MySQL on a table with 300K rows. The migrations are fully backwards-compatible and no table locks or existing operations on the table are impacted by this upgrade. Zero downtime is expected when upgrading to this release. The SQL queries included are CREATE INDEX idx_sidebarchannels_categoryid ON SidebarChannels(CategoryId); for MYSQL and CREATE INDEX CONCURRENTLY IF NOT EXISTS idx_sidebarchannels_categoryid ON sidebarchannels(categoryid); for PostgreSQL.10.5.4, released 2025-04-29
10.5.3, released 2025-04-15
10.5.2, released 2025-03-17
10.5.1, released 2025-02-19
ServiceSettings.EnableWebHubChannelIteration was added which allows a user to control the performance of websocket broadcasting. By default, this setting is turned off. If it is turned on, it improves the websocket broadcasting performance at the expense of poor performance when users join/leave a channel. It is not recommended to turn it on unless you have atleast 200,000 concurrent users actively using Mattermost.10.5.0, released 2025-02-14
PluginLinkComponent in the web app have been changed to unmount link tooltips from the DOM by default, significantly improving performance. Plugins that register link tooltips using registerLinkTooltipComponent will experience changes in how tooltip components are managed—they are now only mounted when a link is hovered over or focused. As a result, plugins may need to update their components to properly handle mounting and unmounting scenarios. For example, changes were made in mattermost-plugin-jira, where componentDidUpdate lifecycle hook was replaced with componentDidMount. If your plugin’s tooltip component is a functional React component, there is a high chance that this behavior will be handled automatically, as it would be managed by useEffect with an empty dependency array.If you upgrade from a release earlier than v10.3, please read the other Important Upgrade Notes.
CustomProfileAttributes. Once enabled, administrators can access the System Properties section in the System Console to create and manage custom user profile fields. The initial release supports text fields only.Fallback field to PluginSettingsSection that controls whether the settings defined under the section should still render as fallback when the plugin is disabled.form-data from @mattermost/client.DeleteAt non-zero value in the database might cause issues with several APIs.pluginapi.store.GetReplicaDB returned nil if masterDB was not initialized.SqlPostStore.PermanentDeletebyUser where no error was returned when 10K posts were exceeded.TeamSettings.ExperimentalViewArchivedChannels was enabled. If there are old channels which were archived before a bulk index was run, users would need to purge indexes, and do bulk index again. Because those old archived channels are removed from the index when a bulk index is run.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
essageExportSettings in config.json:
ComplianceExportDirectoryFormat, ComplianceExportPath, ComplianceExportPathCLI, ComplianceExportChannelBatchSizeDefault, and ComplianceExportChannelHistoryBatchSizeDefault for compliance export overhaul.GetUsersInChannelDuring now accepts a slice; added GetChannelsWithActivityDuring.api/v4/config endpoint:
remove_defaults (filters out default values).remove_masked (removes masked fields).v1.23.12.ServiceSettings.EnableWebHubChannelIteration was added which allows a user to control the performance of websocket broadcasting. By default, this setting is turned off. If it is turned on, it improves the websocket broadcasting performance at the expense of poor performance when users join/leave a channel. It is not recommended to turn it on unless you have atleast 200,000 concurrent users actively using Mattermost.LinkMetadata table.If you upgrade from a release earlier than v10.3, please read the other Important Upgrade Notes.
New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
LocalizationSettings in config.json:
EnableExperimentalLocales configuration setting that controls whether to allow the selection of experimental (e.g., in progress) languages.CacheSettings in config.json:
CacheType: This can be either lru or redis. lru is the default choice which will use the in-memory cache store that we use currently.RedisAddress: The hostname of the Redis host.RedisPassword: The password of the Redis host (can be left blank if there is no password).RedisDB: The database of the Redis host. Typically 0.DisableClientCache: This can be set to true if you decide to disable the client-side cache of Redis. Typically there is no need to do this in production, and this is mainly used as a test option.FileSettings in config.json:
AmazonS3StorageClass and ExportAmazonS3StorageClass, both default to "" to preserve the current behavior. Administrators may configure this storage class to the storage class required by their S3 solution.GET api/v4/users/{user_id:[A-Za-z0-9]+}/teams/{team_id:[A-Za-z0-9]+}/threads.server_hostname field to the websocket HELLO event.v1.22.6.ServiceSettings.EnableWebHubChannelIteration was added which allows a user to control the performance of websocket broadcasting. By default, this setting is turned off. If it is turned on, it improves the websocket broadcasting performance at the expense of poor performance when users join/leave a channel. It is not recommended to turn it on unless you have atleast 200,000 concurrent users actively using Mattermost.If you upgrade from a release earlier than v10.2, please read the other Important Upgrade Notes.
fetchMissingUsers option to PostUtils.messageHtmlToComponent for use by plugins.ImagePreview and SizeAwareImage components.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
ServiceSettings in config.json:
ScheduledPosts to enable the feature to schedule and send message in the future.v1.22.6.opensearch-project/opensearch-go to https://github.com/mattermost/mattermost.If you upgrade from a release earlier than v10.0, please read the other Important Upgrade Notes.
useMilitaryTime to false to default to 12-hour time format unless the user's preference from data.Value is true. When a notification email is sent to a user, the time should now default to the 12-hour format unless otherwise stated by the user.permanent to DELETE /api/v4/posts/<post-id>, and set permanent to true in order to permanently delete a post and its attachments.mmctl post delete <post-id>, in order to permanently delete a post and its attachments.NewWebConn.EnableTesting was enabled.registerSlashCommandWillBePostedHook that caused errors to surface in case an expected empty object was returned.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
ServiceSettings in config.json:
EnableAPIPostDeletion in order to enable/disable post deletion. This configuration setting does not need to be enabled when running mmctl in local mode.EnableDesktopLandingPage to allow the desktop app landing page to be disabled.NativeAppSettings in config.json:
MobileExternalBrowser that tells the Mobile app to perform SSO Authentication using the external default browser.v1.22.6.registerSlashCommandWillBePostedHook that caused errors to surface in case an expected empty object was returned.If you upgrade from a release earlier than v10.0, please read the other Important Upgrade Notes.
DeleteAt field for SharedChannelRemotes and RemoteClusters.413: Request Entity Too Large HTTP status code for a plugin upload that is too large.--local mode support in MMCTL to handle user preferences.@ and ~ in the in: search modifier without affecting search results.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
ExperimentalSettings in config.json:
YoutubeReferrerPolicy to fix an issue where YouTube previews showed an “Video Unavailable” error instead of the video.ConnectedWorkspacesSettings in config.json:
DisableSharedChannelsStatusSync to add status sync support to Shared Channels.ConnectedWorkspacesSettings in config.json:
MaxPostsPerSync configuration property./api/v4/client_perf endpoint.v1.22.6.registerSlashCommandWillBePostedHook that caused errors to surface in case an expected empty object was returned.Channel Moderation to Advanced Access Control in the channel management section in the System Console./api/v4/image endpoint when the image proxy is disabled.Config.ProductSettings, LdapSettings.Trace, and AdvancedLoggingConfig configuration fields.pageSize query parameter from most API endpoints.If you upgrade from a release earlier than v9.11, please read the other Important Upgrade Notes.
mmctl webhooks list to paginate past 200 results.LiveIndexingBatchSize to 1. Now we respect the config and index synchronously if the value is set to 1.New setting options were added to config.json. Below is a list of the additions and their default values on install. The settings can be modified in config.json, or the System Console when available.
ServiceSettings in config.json:
MaximumURLLength to remove the hardcoded URL length limit.Config.ProductSettings.EnablePreviewFeatures setting.LdapSettings.Trace setting.AdvancedLoggingConfig setting.include_total_count to API endpoint GET /api/v4/hooks/incoming.v1.21.8.redis/rueidis to https://github.com/mattermost/mattermost.