PT-2026-48939 · Mattermost · Mattermost

·

CVE-2026-6961

·

Published

2026-06-12

·

Updated

2026-06-18

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Mattermost versions 11.6.0 through 11.6.1 Mattermost versions 11.5.0 through 11.5.4 Mattermost versions 10.11.0 through 10.11.16
Description Insufficient sanitization of the FileInfo.Name variable received from federated peers during shared channel file synchronization allows an attacker controlling a federated server to perform a path traversal attack. This enables the attacker to write files to arbitrary locations within the target server's filestore by using path traversal sequences in the filename field.
Recommendations Update versions 11.6.0 through 11.6.1 to a newer version. Update versions 11.5.0 through 11.5.4 to a newer version. Update versions 10.11.0 through 10.11.16 to a newer version.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6961

Affected Products

Mattermost