CVE-2026-3473EPSS p14.6%

CVE-2026-3473CVE-2026-3473

mattermost / mattermost_server

Description

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620

Scoring

CVSS 5.9 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
EPSS0.25% probability of exploitation · percentile 14.6% · 2026-10-05T12:00:23Z
Last modified2026-07-23
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.