CVE-2026-7521: SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-00666
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.4 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.6 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.21
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7521?
The severity of CVE-2026-7521 is medium with a score of 5.5.
How do I fix CVE-2026-7521?
To fix CVE-2026-7521, upgrade Mattermost to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-7521?
Administrators using Mattermost versions 11.8.x, 11.7.x, 11.6.x, and 10.11.x are affected by CVE-2026-7521.
What type of vulnerability is CVE-2026-7521?
CVE-2026-7521 is a Path Traversal vulnerability.
What can be exploited in CVE-2026-7521?
CVE-2026-7521 allows an admin to delete arbitrary files outside the config directory via the remove file endpoint.