Junglewise Threat Intelligence

CVE-2026-7521: Mattermost path traversal in file deletion endpoint

CVE-2026-7521 · Severity: medium · CVSS 5.5 · Published 2026-07-28

Technologies: Mattermost. Vendors: Mattermost.

Executive brief

Mattermost, a collaboration platform for secure team communication, contains a vulnerability that allows administrative users to delete files they should not have access to. An administrator with specific console permissions could delete critical system files outside of the application's intended configuration directory. This could lead to service instability, data loss, or a complete system outage. Organizations should update to the latest patched versions to prevent unauthorized file removal.

Technical details

A path traversal vulnerability (CWE-22) exists in Mattermost's file removal endpoint. The application fails to verify the file deletion path, which allows an authenticated attacker with administrative privileges (specifically SAML system-console write permissions) to supply paths outside the intended configuration directory. By exploiting this, an attacker can delete arbitrary files on the underlying server, potentially causing a denial of service or integrity issues. The vulnerability is addressed in versions 11.9.0, 11.8.1, 11.7.4, 11.6.6, and 10.11.21.

Affected products

  • Mattermost Mattermost 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory

References

Related threats