File Path Vulnerability in Mattermost by Mattermost Inc.
CVE-2026-6957

8HIGH

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
27 May 2026

What is CVE-2026-6957?

Mattermost Plugins versions up to 1.1.5 are susceptible to a vulnerability that results from inadequate sanitization of filenames obtained from federated peers. When an administrator from a remote Mattermost server sends a crafted filename via the attachment sync protocol of shared channels, it enables the attacker to manipulate file paths on the target server. This flaw allows an attacker to write files to arbitrary locations within the server's filestore, potentially leading to unauthorized access to sensitive data or other malicious actions.

Affected Version(s)

Mattermost 0 <= 1.1.5

Mattermost .0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hassan Mohammed
.