CVE-2026-4858

EUVD-2026-31242
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user  to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
MattermostCNA
8 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
mattermostmattermost_server
10.11.0 ≤
𝑥
< 10.11.15
mattermostmattermost_server
11.4.0 ≤
𝑥
< 11.4.5
mattermostmattermost_server
11.5.0 ≤
𝑥
< 11.5.4
mattermostmattermost_server
11.6.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mattermostmattermost
𝑥
≤ 11.6.0
CNA
mattermostmattermost
11.5.0 ≤
𝑥
≤ 11.5.3
CNA
mattermostmattermost
11.4.0 ≤
𝑥
≤ 11.4.4
CNA
mattermostmattermost
10.11.0 ≤
𝑥
≤ 10.11.14
CNA