CVE-2026-3112: Arbitrary File Read via Advanced Logging Support Packet
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced Logging file target paths which allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in support packet generation. Mattermost Advisory ID: MMSA-2025-00562
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3112?
CVE-2026-3112 has a medium severity rating due to the potential for arbitrary file reading by unauthorized users.
How do I fix CVE-2026-3112?
To fix CVE-2026-3112, upgrade to Mattermost versions 11.4.1 or later, 11.3.2 or later, 11.2.4 or later, or 10.11.12 or later.
What versions are affected by CVE-2026-3112?
CVE-2026-3112 affects Mattermost versions 11.4.0 and earlier, 11.3.1 and earlier, 11.2.3 and earlier, and 10.11.11 and earlier.
What causes CVE-2026-3112?
CVE-2026-3112 is caused by a failure to validate target file paths in the Advanced Logging feature of Mattermost, allowing unauthorized file access.
Who is impacted by CVE-2026-3112?
System administrators using the affected versions of Mattermost may be impacted by CVE-2026-3112 due to the risk of arbitrary file reading.