CVE-2026-3524HIGH 8.8EPSS p29.5%

CVE-2026-3524CVE-2026-3524

Description

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.38% probability of exploitation · percentile 29.5% · 2026-06-19T12:03:05Z
Published2026-04-06
Last modified2026-04-07

Underlying weaknesses· 1

CWE-862

References

  1. https://mattermost.com/security-updates

1

TypeTargetConfidenceTier
WeaknessMissing Authorizationcwe-8620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-3116
CVE
CVE-2026-6346
CVE
CVE-2026-3109
CVE
CVE-2025-25068
CVE
CVE-2026-4858
CVE
CVE-2026-4915
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.