CVE-2026-7521

Summary

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-00666

Affected Software

VendorProductVersion RangeStatus
MattermostMattermost11.8.0 <= 11.8.0affected
MattermostMattermost11.7.0 <= 11.7.3affected
MattermostMattermost11.6.0 <= 11.6.5affected
MattermostMattermost10.11.0 <= 10.11.20affected
MattermostMattermost11.9.0unaffected
MattermostMattermost11.8.1unaffected
MattermostMattermost11.7.4unaffected
MattermostMattermost11.6.6unaffected
MattermostMattermost10.11.21unaffected

Weaknesses

  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References