SEPTEMBER 22, 2026
Live Feed
Back to database
Case File

CVE-2026-3473

MEDIUM · CVSS 5.9 EPSS 0.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-22 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.9. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-3473
Severity
MEDIUM
CVSS
5.9
EPSS
0.15%

Original NVD Description

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620

Related CVEs

Other vulnerabilities affecting the same vendor(s)