Executive brief
Mattermost, a collaboration platform for secure team communication, contains a vulnerability that allows administrative users to delete files they should not have access to. An administrator with specific console permissions could delete critical system files outside of the application's intended configuration directory. This could lead to service instability, data loss, or a complete system outage. Organizations should update to the latest patched versions to prevent unauthorized file removal.
Technical details
A path traversal vulnerability (CWE-22) exists in Mattermost's file removal endpoint. The application fails to verify the file deletion path, which allows an authenticated attacker with administrative privileges (specifically SAML system-console write permissions) to supply paths outside the intended configuration directory. By exploiting this, an attacker can delete arbitrary files on the underlying server, potentially causing a denial of service or integrity issues. The vulnerability is addressed in versions 11.9.0, 11.8.1, 11.7.4, 11.6.6, and 10.11.21.
Affected products
- Mattermost Mattermost 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory