CVE-2026-4858 PUBLISHED

Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.

Assigner: Mattermost
Reserved: 25.03.2026 Published: 21.05.2026 Updated: 21.05.2026

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 8

Product Status

Vendor Mattermost
Product Mattermost
Versions Default: unaffected
  • affected from 11.6.0 to 11.6.0 (incl.)
  • affected from 11.5.0 to 11.5.3 (incl.)
  • affected from 11.4.0 to 11.4.4 (incl.)
  • affected from 10.11.0 to 10.11.14 (incl.)
  • Version 11.7.0 is unaffected
  • Version 11.6.1 is unaffected
  • Version 11.5.4 is unaffected
  • Version 11.4.5 is unaffected
  • Version 10.11.15 is unaffected

Solutions

Update Mattermost to versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, 10.11.15 or higher.

Credits

  • daw10 finder

References

Problem Types

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE