Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 May 2026, 19:43
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:11.6.0:*:*:*:*:*:*:* |
|
| First Time |
Mattermost mattermost Server
Mattermost |
|
| References | () https://mattermost.com/security-updates - Vendor Advisory |
21 May 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-21 09:16
Updated : 2026-05-21 19:43
NVD link : CVE-2026-4858
Mitre link : CVE-2026-4858
CVE.ORG link : CVE-2026-4858
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
