SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-7521

MEDIUM · CVSS 5.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to inadequate verification of file deletion paths, allowing an admin with SAML system-console write permissions to delete arbitrary files outside the config directory via the remove file endpoint. This could lead to unauthorized data loss or system disruption. Organizations using affected Mattermost versions should prioritize patching to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-7521
Severity
MEDIUM
CVSS
5.5
EPSS
0.28%

Original NVD Description

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-00666

Related CVEs

Other vulnerabilities affecting the same vendor(s)