CVE-2026-3473
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620
- Affected products
- Mattermost
- Mattermost Mattermost Server
- < 10.11.15, 11.4.5, 11.5.4, 11.6.1
- CVSS 3.1
- 7.1 HIGH
- EPSS
- 0.1% (5th percentile)
- Weakness
- CWE-639
- NVD status
- Analyzed
- Published
- 2026-05-22
Fix
Update Mattermost to versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, 10.11.15 or higher.
CVE-2026-3473 at NVD
No indexed exploits for CVE-2026-3473 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-3473 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.