CVE-2026-28736
EUVD-2026-1865303.04.2026, 14:16
** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. This allows an authenticated attacker who knows a victim's fileID to read the content of the file. NOTE: Focalboard as a standalone product is not maintained and no fix will be issued.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mattermost | focalboard | 𝑥 ≤ 8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration