PatchSiren cyber security CVE debrief
CVE-2026-3524 Mattermost CVE debrief
Mattermost Plugin Legal Hold versions <=1.1.4 are vulnerable due to a failed authorization check in ServeHTTP, allowing authenticated attackers to access, create, download, and delete legal hold data via crafted API requests. This vulnerability affects Mattermost Plugin Legal Hold deployments. The CVE record was published on 2026-04-06T13:17:18.417Z. Users should verify affected deployments and review vendor guidance.
- Vendor
- Mattermost
- Product
- Legal Hold
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-08-06
Who should care
Users of Mattermost Plugin Legal Hold versions <=1.1.4, administrators responsible for plugin management and security, security teams monitoring for potential unauthorized data access, and operators managing affected deployments should be aware of this vulnerability and take necessary actions to protect their environments. This includes reviewing and restricting API requests, implementing compensating controls, and monitoring for suspicious activity.
Technical summary
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP, allowing authenticated attackers to access, create, download, and delete legal hold data via crafted API requests. Defenders should focus on restricting API requests and implementing compensating controls. The vulnerability affects Mattermost Plugin Legal Hold deployments.
Defensive priority
Authenticated attackers can access, create, download, and delete legal hold data via crafted API requests due to a failed authorization check in Mattermost Plugin Legal Hold versions <=1.1.4.
Recommended defensive actions
- Verify Mattermost Plugin Legal Hold version and upgrade to 1.1.5 or later if possible
- Review and restrict API requests to the plugin's endpoints
- Monitor for suspicious activity related to legal hold data
- Implement compensating controls for authentication and authorization
- Review vendor advisories for additional guidance
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE-2026-3524 record indicates Mattermost Plugin Legal Hold versions <=1.1.4 are vulnerable due to a failed authorization check. Verification is recommended via vendor advisories and inventory checks. Evidence is limited, and defenders should verify affected deployments, review vendor guidance, and monitor for suspicious activity related to legal hold data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-3524 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-3524
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-3524 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3524
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://mattermost.com/security-updates
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.