Back to overview

CVE-2026-7521

MEDIUM
5.5
CVSS 3.1
Description
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-00666

Metadata

CVE ID
CVE-2026-7521
State
PUBLISHED
Assigner
Mattermost
Reserved
2026-04-30 16:51 UTC
Published
2026-07-28 13:58 UTC
Last updated
2026-07-28 14:48 UTC
Primary CWE
CWE-22
CWE-22: Improper Limitation of a Pathname to a Restricted Di…
Vendor / Product
Mattermost / Mattermost
Sources
cve.org  ·  NVD

Severity & Metrics

5.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Mattermost Mattermost 11.8.0 ≤ 11.8.0, 11.7.0 ≤ 11.7.3, 11.6.0 ≤ 11.6.5, 10.11.0 ≤ 10.11.20 …
Weakness (CWE)
CWESourceDescription
CWE-22 cna CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.5 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
References (1)
Back to overview