PT-2026-30601 · Mattermost · Mattermost Plugin Legal Hold

·

CVE-2026-3524

·

Published

2026-04-06

·

Updated

2026-08-06

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mattermost Plugin Legal Hold versions prior to 1.1.5
Description An issue exists where the software fails to halt request processing after a failed authorization check in the ServeHTTP() function. This allows an authenticated attacker to access, create, download, and delete legal hold data by sending crafted API requests to the plugin endpoints.
Recommendations Update to a version newer than 1.1.4.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3524

Affected Products

Mattermost Plugin Legal Hold