6.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Description
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced Logging file target paths which allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in support packet generation. Mattermost Advisory ID: MMSA-2025-00562
Basic Information
ID
CVE-2026-3112
Source
Mattermost
Published
Mar 26, 2026 at 16:29
Modified
Mar 26, 2026 at 16:51
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
11.4.0
Affected Versions
Mattermost Mattermost 11.4.0
Mattermost Mattermost 11.3.0
Mattermost Mattermost 11.2.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 11.3.0
Mattermost Mattermost 11.2.0
Mattermost Mattermost 10.11.0