Description
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-00666
Published: 2026-07-28
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost versions 11.8.x through 10.11.x contain a path‑traversal vulnerability in the remove file API that allows an administrator with SAML system‑console write permissions to specify a file path outside the configuration directory and delete that file. This flaw permits arbitrary file removal on the host, which can lead to data loss, configuration corruption, or enable further compromise if the deleted files contain credentials or executables. The weakness is classified as CWE‑22 paths and is not a direct code‑execution flaw but can undermine system integrity.

Affected Systems

The flaw affects Mattermost Enterprise and community editions in the following versions: 11.8.x up to 11.8.0, 11.7.x up to 11.7.3, 11.6.x up to 11.6.5, and 10.11.x up to 10.11.20. The vulnerability exists only for installations that expose the remove file endpoint to users with SAML system‑console write rights.

Risk and Exploitability

The CVSS score is 5.5, indicating moderate severity. The EPSS score is less than 1%, meaning exploitation is currently considered low probability. The vulnerability is not listed in the CISA KEV catalog. Execution requires administrative privileges and the ability to access the SAML system‑console write interface; therefore, the risk is confined to environments where such privileges are distributed. In the event of privilege misuse or compromise, the attacker could delete critical files, potentially leading to service disruption or enabling further attacks.

Generated by OpenCVE AI on August 3, 2026 at 14:56 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 11.8.1, 11.7.4, 11.6.6, 10.11.21 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to version 11.9.0, 11.8.1, 11.7.4, 11.6.6, or 10.11.21 or newer.
  • Limit SAML system‑console write permissions to trusted administrators on the server.
  • If the remove file endpoint is not required, disable it or firewall it to prevent unintended exposure.

Generated by OpenCVE AI on August 3, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-00666
Title SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Mattermost Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-28T14:48:13.408Z

Reserved: 2026-04-30T16:51:23.295Z

Link: CVE-2026-7521

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T15:17:51.510

Modified: 2026-07-29T15:06:39.703

Link: CVE-2026-7521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:00:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')