PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3524 Mattermost CVE debrief

Mattermost Plugin Legal Hold versions <=1.1.4 are vulnerable due to a failed authorization check in ServeHTTP, allowing authenticated attackers to access, create, download, and delete legal hold data via crafted API requests. This vulnerability affects Mattermost Plugin Legal Hold deployments. The CVE record was published on 2026-04-06T13:17:18.417Z. Users should verify affected deployments and review vendor guidance.

Vendor
Mattermost
Product
Legal Hold
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-08-06
Advisory published
2026-04-06
Advisory updated
2026-08-06

Who should care

Users of Mattermost Plugin Legal Hold versions <=1.1.4, administrators responsible for plugin management and security, security teams monitoring for potential unauthorized data access, and operators managing affected deployments should be aware of this vulnerability and take necessary actions to protect their environments. This includes reviewing and restricting API requests, implementing compensating controls, and monitoring for suspicious activity.

Technical summary

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP, allowing authenticated attackers to access, create, download, and delete legal hold data via crafted API requests. Defenders should focus on restricting API requests and implementing compensating controls. The vulnerability affects Mattermost Plugin Legal Hold deployments.

Defensive priority

Authenticated attackers can access, create, download, and delete legal hold data via crafted API requests due to a failed authorization check in Mattermost Plugin Legal Hold versions <=1.1.4.

Recommended defensive actions

  • Verify Mattermost Plugin Legal Hold version and upgrade to 1.1.5 or later if possible
  • Review and restrict API requests to the plugin's endpoints
  • Monitor for suspicious activity related to legal hold data
  • Implement compensating controls for authentication and authorization
  • Review vendor advisories for additional guidance
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE-2026-3524 record indicates Mattermost Plugin Legal Hold versions <=1.1.4 are vulnerable due to a failed authorization check. Verification is recommended via vendor advisories and inventory checks. Evidence is limited, and defenders should verify affected deployments, review vendor guidance, and monitor for suspicious activity related to legal hold data.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T13:17:18.417Z and has not been modified since then.