PT-2026-52708 · Mattermost · Mattermost

·

CVE-2026-13426

·

Published

2026-06-26

·

Updated

2026-06-26

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions github.com/mattermost/mattermost/server/public versions prior to 0.1.22
Description The software fails to validate path parameters when constructing API route paths. This allows an attacker to redirect API calls to unintended endpoints by using crafted IDs that include path traversal components, which are sequences of characters used to access files or directories outside the intended folder.
Recommendations Update github.com/mattermost/mattermost/server/public to version 0.1.22 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13426

Affected Products

Mattermost