CVE-2026-3524
EUVD-2026-1923106.04.2026, 13:17
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mattermost | legal_hold | 𝑥 < 1.1.5 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mattermost | mattermost | 𝑥 ≤ 1.1.4 | CNA |
Common Weakness Enumeration
References