Improper file ownership validation in the Boards API allows unauthorised file access
Published May 22, 2026
7.1
HIGHCVSS 3.1
EPSS 0.25%
Description
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620
Affected products
-
- Version 10.11.0StatusaffectedConstraints<=10.11.14
- Version 11.4.0StatusaffectedConstraints<=11.4.4
- Version 11.5.0StatusaffectedConstraints<=11.5.3
- Version 11.6.0StatusaffectedConstraints<=11.6.0
- Version 10.11.15StatusunaffectedConstraints-
- Version 11.4.5StatusunaffectedConstraints-
- Version 11.5.4StatusunaffectedConstraints-
- Version 11.6.1StatusunaffectedConstraints-
- Version 11.7.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mattermost | Mattermost | unaffected |
|
- ≥ 10.11.0 · < 10.11.15
- ≥ 11.4.0 · < 11.4.5
- ≥ 11.5.0 · < 11.5.4
- ≥ 11.6.0 · < 11.6.1
No data.
No Red Hat product state for this CVE.
github.com/mattermost/mattermost-server
Go
Introduced 11.4.0+incompatible Fixed 11.4.5+incompatiblegithub.com/mattermost/mattermost-server
Go
Introduced 11.6.0+incompatible Fixed 11.6.1+incompatiblegithub.com/mattermost/mattermost-server
Go
Introduced 10.11.0+incompatible Fixed 10.11.15+incompatiblegithub.com/mattermost/mattermost-server
Go
Introduced 11.5.0+incompatible Fixed 11.5.4+incompatible
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/mattermost/mattermost-server | 11.4.0+incompatible | 11.4.5+incompatible |
| Go | github.com/mattermost/mattermost-server | 11.6.0+incompatible | 11.6.1+incompatible |
| Go | github.com/mattermost/mattermost-server | 10.11.0+incompatible | 10.11.15+incompatible |
| Go | github.com/mattermost/mattermost-server | 11.5.0+incompatible | 11.5.4+incompatible |
Remediation
Vendor solution
Update Mattermost to versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, 10.11.15 or higher.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31429 Advisory
- https://github.com/advisories/GHSA-7pf2-9c95-w332 Advisory
- https://mattermost.com/security-updates vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-3473
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31429 | Advisory | |
| https://github.com/advisories/GHSA-7pf2-9c95-w332 | Advisory | |
| https://mattermost.com/security-updates | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-3473 |
Change history (0)
No recorded changes yet.