File Deletion Vulnerability in Mattermost by Mattermost
CVE-2026-7521
5.5MEDIUM
What is CVE-2026-7521?
The Mattermost platform has a significant issue where specific versions fail to properly verify the file deletion path. This vulnerability enables an administrator with SAML system-console write permissions to delete arbitrary files outside the intended config directory via the remove file endpoint. This flaw could lead to unauthorized file manipulation and poses a risk to the overall stability and security of the server environment.
Affected Version(s)
Mattermost 11.8.0
Mattermost 11.7.0 <= 11.7.3
Mattermost 11.6.0 <= 11.6.5