Mattermost · Mattermost Plugin Legal Hold · CVE-2026-3524
**Name of the Vulnerable Software and Affected Versions**
Mattermost Plugin Legal Hold versions prior to 1.1.5
**Description**
An issue exists where the software fails to halt request processing after a failed authorization check in the `ServeHTTP()` function. This allows an authenticated attacker to access, create, download, and delete legal hold data by sending crafted API requests to the plugin endpoints.
**Recommendations**
Update to a version newer than 1.1.4.