CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2026-7521

MEDIUM
5.5
CVSS Severity Score
EPSS Score0.2830%
EPSS Percentile20.60th
Published2026-07-28
Last Modified2026-07-29
Data SourcesNVDFIRST.org EPSS

Vulnerability Description

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-00666

Affected Platforms (CPE)

📦
Mattermost

Mattermost Server

>= 10.11.0 and < 10.11.21>= 11.6.0 and < 11.6.6>= 11.7.0 and < 11.7.4>= 11.8.0 and < 11.8.1

References & Advisories

相關漏洞威脅