Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-3473

MEDIUM mattermost mattermost_server NVD
CVSS Score 5.9
Severity MEDIUM
Published May 22, 2026
Vendor mattermost

Description

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620

References