EXPOSURES › CVE-2026-4858
CVE-2026-4858
HIGH
DETAIL
SourceNVD · cve
Published2026-05-21
CVSS8.0
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-4858 ↗
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
PLAYERS IMPLICATED
DESCRIPTION
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.