CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.9. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-3473
Severity
MEDIUM
CVSS
5.9
EPSS
0.15%
Original NVD Description
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620
Related CVEs
Other vulnerabilities affecting the same vendor(s)