Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 May 2026, 17:21
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-22 11:16
Updated : 2026-05-22 17:21
NVD link : CVE-2026-3473
Mitre link : CVE-2026-3473
CVE.ORG link : CVE-2026-3473
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
