PT-2026-65500 · Mattermost · Mattermost
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Mattermost version 11.8.0
Mattermost versions 11.7.x through 11.7.3
Mattermost versions 11.6.x through 11.6.5
Mattermost versions 10.11.x through 10.11.20
Description
An issue exists where the system fails to verify the file deletion path. This allows an administrator with SAML system-console write permissions to delete arbitrary files outside the config directory from the server using the 'remove file' endpoint.
Recommendations
Update Mattermost version 11.8.0 to a newer version.
Update Mattermost versions 11.7.x through 11.7.3 to a newer version.
Update Mattermost versions 11.6.x through 11.6.5 to a newer version.
Update Mattermost versions 10.11.x through 10.11.20 to a newer version.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost