CVE-2026-3113: mmctl export download command doesn’t restrict permissions to created file to file owner
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost Advisory ID: MMSA-2026-00593
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3113?
CVE-2026-3113 has a medium severity rating due to improper permission settings that can expose sensitive data.
How do I fix CVE-2026-3113?
To fix CVE-2026-3113, upgrade Mattermost to versions higher than 11.4.0, 11.3.1, 11.2.3, or 10.11.11.
What versions of Mattermost are affected by CVE-2026-3113?
Mattermost versions 11.4.x up to 11.4.0, 11.3.x up to 11.3.1, 11.2.x up to 11.2.3, and 10.11.x up to 10.11.11 are affected by CVE-2026-3113.
What kind of issue does CVE-2026-3113 represent?
CVE-2026-3113 represents an issue of improper access control where downloaded bulk exports are not restricted to the file owner.
Could CVE-2026-3113 lead to data leaks?
Yes, CVE-2026-3113 could lead to potential data leaks as local users may gain unauthorized access to files.