CVE-2026-3473

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

22 May 2026, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-22 11:16

Updated : 2026-05-22 17:21


NVD link : CVE-2026-3473

Mitre link : CVE-2026-3473

CVE.ORG link : CVE-2026-3473


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-639

Authorization Bypass Through User-Controlled Key