CVE-2026-7521
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Mattermost Server

Vulnerability report for CVE-2026-7521, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-00666

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.8.0 (inc)
mattermost mattermost to 11.7.3 (inc)
mattermost mattermost to 11.6.5 (inc)
mattermost mattermost to 10.11.20 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Mattermost versions 11.8.0 and below, 11.7.3 and below, 11.6.5 and below, and 10.11.20 and below. It allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint due to improper verification of file deletion paths.

Impact Analysis

An attacker with admin privileges could delete critical system files, leading to service disruption, data loss, or potential unauthorized access to sensitive information. The impact severity is moderate with a CVSS score of 5.5, indicating limited confidentiality impact but high availability impact.

Compliance Impact

This vulnerability could lead to unauthorized file deletion, potentially violating data integrity and availability requirements under GDPR and HIPAA. Organizations may face compliance violations if sensitive data or logs are deleted, impacting audit trails and data protection measures.

Mitigation Strategies

Update Mattermost to a patched version (11.8.1 or later, 11.7.4 or later, 11.6.6 or later, or 10.11.21 or later) to address the file deletion vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7521. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart