Untriaged
Permalink
CVE-2026-3473
5.9 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
Improper file ownership validation in the Boards API allows unauthorised file access
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620
References
-
MMSA-2026-00620 vendor-advisory
Affected products
Mattermost
- =<11.6.0
- =<11.5.3
- =<10.11.14
- ==11.5.4
- ==11.7.0
- ==11.6.1
- ==10.11.15
- ==11.4.5
- =<11.4.4
Matching in nixpkgs
pkgs.mattermost
Open source platform for secure collaboration across the entire software development lifecycle
pkgs.mattermostLatest
Open source platform for secure collaboration across the entire software development lifecycle
pkgs.mattermost-desktop
Mattermost Desktop client
pkgs.python312Packages.mattermostdriver
Python Mattermost Driver
pkgs.python313Packages.mattermostdriver
Python Mattermost Driver
pkgs.python314Packages.mattermostdriver
Python Mattermost Driver
Package maintainers
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@ryantm Ryan Mulligan <ryan@ryantm.com>
-
@mgdelacroix Miguel de la Cruz <mgdelacroix@gmail.com>
-
@jokogr Ioannis Koutras <ioannis.koutras@gmail.com>
-
@yayayayaka Yaya <github@uwu.is>
-
@liff Olli Helenius <liff@iki.fi>
-
@globin Robin Gloster <mail@glob.in>