Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2402 articles · 111888 vulns · 38/41 feeds (7d)
← Back to list
4.3
CVE-2026-4265PATCHED
mattermost · mattermost_server

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack u

Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Mattermost Advisory ID: MMSA-2025-00553

Affected Products

VendorProductVersions
mattermostmattermost_server< 10.11.11, < 11.2.3, < 11.3.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mattermostmattermostcert_advisory90%

References

  • https://mattermost.com/security-updates(Vendor Advisory)

Related News (1 articles)

Tier B
BSI Advisories4d ago
[UPDATE] [mittel] Mattermost: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.11.1111.2.311.3.1
CWECWE-863
PublishedMar 16, 2026
Last enriched18d ago
Trending Score13
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-3590EXP
Race Condition in Guest Magic Link Authentication Allows Token Reuse
Trending: 72
MEDIUMCVE-2026-28741EXP
CSRF Protection Bypass Allows Updating a User's Authentication Method
Trending: 22
HIGHCVE-2026-3524EXP
Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission Check
Trending: 10
LOWCVE-2026-27769
Connected Workspaces: Malicious remote server can manipulate arbitrary user's status
Trending: 10
LOWCVE-2026-21388
Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint
Trending: 9

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 16, 2026
Patch Available
Mar 18, 2026
Discovered by ZDM
Apr 1, 2026