PatchSiren cyber security CVE debrief
CVE-2026-3524 Mattermost CVE debrief
Mattermost Plugin Legal Hold versions <=1.1.4 are vulnerable due to a failed authorization check in ServeHTTP, allowing authenticated attackers to access, create, download, and delete legal hold data via crafted API requests. This vulnerability affects Mattermost Plugin Legal Hold deployments. The CVE record was published on 2026-04-06T13:17:18.417Z. Users should verify affected deployments and review vendor guidance.
- Vendor
- Mattermost
- Product
- Legal Hold
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-08-06
Who should care
Users of Mattermost Plugin Legal Hold versions <=1.1.4, administrators responsible for plugin management and security, security teams monitoring for potential unauthorized data access, and operators managing affected deployments should be aware of this vulnerability and take necessary actions to protect their environments. This includes reviewing and restricting API requests, implementing compensating controls, and monitoring for suspicious activity.
Technical summary
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP, allowing authenticated attackers to access, create, download, and delete legal hold data via crafted API requests. Defenders should focus on restricting API requests and implementing compensating controls. The vulnerability affects Mattermost Plugin Legal Hold deployments.
Defensive priority
Authenticated attackers can access, create, download, and delete legal hold data via crafted API requests due to a failed authorization check in Mattermost Plugin Legal Hold versions <=1.1.4.
Recommended defensive actions
- Verify Mattermost Plugin Legal Hold version and upgrade to 1.1.5 or later if possible
- Review and restrict API requests to the plugin's endpoints
- Monitor for suspicious activity related to legal hold data
- Implement compensating controls for authentication and authorization
- Review vendor advisories for additional guidance
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE-2026-3524 record indicates Mattermost Plugin Legal Hold versions <=1.1.4 are vulnerable due to a failed authorization check. Verification is recommended via vendor advisories and inventory checks. Evidence is limited, and defenders should verify affected deployments, review vendor guidance, and monitor for suspicious activity related to legal hold data.
Official resources
-
CVE-2026-3524 CVE record
CVE.org
-
CVE-2026-3524 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T13:17:18.417Z and has not been modified since then.