CVE-2026-3473

MEDIUM

Improper file ownership validation in the Boards API allows unauthorised file access

Title source: cna
STIX 2.1

Description

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
MMSA-2026-00620
https://mattermost.com/security-updates

Scores

CVSS v3 5.9
EPSS 0.0003
EPSS Percentile 8.4%
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (9)
Mattermost/Mattermost 10.11.0 - 10.11.14
Mattermost/Mattermost 10.11.15
Mattermost/Mattermost 11.4.0 - 11.4.4
Mattermost/Mattermost 11.4.5
Mattermost/Mattermost 11.5.0 - 11.5.3
Mattermost/Mattermost 11.5.4
Mattermost/Mattermost 11.6.0
Mattermost/Mattermost 11.6.1
Mattermost/Mattermost 11.7.0
Published May 22, 2026
Tracked Since May 22, 2026