CVE-2026-4858

CRITICAL WAF: High
CVSS 9.9 Published: 2026-05-21
CWE-22

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640

WAF Coverage Analysis

Path Traversal High WAF Coverage

OWASP: A01:2021 Broken Access Control

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
mattermostmattermost_server10.11.0 - 10.11.15
mattermostmattermost_server11.4.0 - 11.4.5
mattermostmattermost_server11.5.0 - 11.5.4
mattermostmattermost_server11.6.0

References

Back to CVE Database