Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-06 13:17
Updated : 2026-08-06 14:21
NVD link : CVE-2026-3524
Mitre link : CVE-2026-3524
CVE.ORG link : CVE-2026-3524
JSON object : View
Products Affected
mattermost
- legal_hold
CWE
CWE-862
Missing Authorization
