7.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L
Description
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary locations within the target server's filestore via path traversal sequences in the filename field.. Mattermost Advisory ID: MMSA-2026-00661
Basic Information
ID
CVE-2026-6961
Source
Mattermost
Published
Jun 12, 2026 at 15:56
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
11.6.0
Affected Versions
Mattermost Mattermost 11.6.0
Mattermost Mattermost 11.5.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 11.5.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 10.11.0