CVE-2026-4858: Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.4 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.4.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.15 - Compensating control
If you cannot upgrade immediately, mitigate exposure of integration actions by restricting access to system administration and limiting who can create/use integration action URLs.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4858?
CVE-2026-4858 has a critical severity score of 9.9.
How do I fix CVE-2026-4858?
To remediate CVE-2026-4858, update Mattermost to versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, or 10.11.15 or higher.
What impact does CVE-2026-4858 have on Mattermost?
CVE-2026-4858 allows malicious authenticated users to perform arbitrary API execution via the system admin's authentication token.
Which versions of Mattermost are affected by CVE-2026-4858?
Mattermost versions 11.6.x ≤ 11.6.0, 11.5.x ≤ 11.5.3, 11.4.x ≤ 11.4.4, and 10.11.x ≤ 10.11.14 are affected by CVE-2026-4858.
What is the nature of the vulnerability in CVE-2026-4858?
CVE-2026-4858 is a path traversal vulnerability in integration action URLs.