Junglewise Threat Intelligence

CVE-2026-3473: Mattermost Server authorization bypass in Boards API

CVE-2026-3473 · Severity: high · CVSS 7.1 · Published 2026-05-22

Technologies: Mattermost Server. Vendors: Mattermost, Go.

Executive brief

Mattermost, a secure collaboration and messaging platform, contains a vulnerability in its Boards feature that could allow unauthorized access to files. An authenticated user can bypass security checks to view or download files belonging to other users or teams if they know the specific file ID. This could lead to the exposure of sensitive documents or private team data.

Technical details

An authorization bypass vulnerability (CWE-639) exists in Mattermost Server's Boards API due to insufficient validation of file ownership and access controls. An authenticated attacker can exploit this by sending crafted API requests containing valid file IDs to access and download files they are not authorized to view, including those belonging to other users or teams. The attack requires the attacker to have a valid account and knowledge of specific file IDs. The issue is resolved in versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, and 10.11.15.

Affected products

  • Mattermost Mattermost Server 11.6.0, 11.5.0 to 11.5.3, 11.4.0 to 11.4.4, 10.11.0 to 10.11.14

Timeline

  • 2026-05-22: advisory: Mattermost Advisory MMSA-2026-00620 published
  • 2026-05-22: disclosed: CVE-2026-3473 published to NVD

References

Related threats