PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3524 Mattermost CVE debrief

Mattermost Plugin Legal Hold versions <=1.1.4 are vulnerable due to a failed authorization check in ServeHTTP, allowing authenticated attackers to access, create, download, and delete legal hold data via crafted API requests. This vulnerability affects Mattermost Plugin Legal Hold deployments. The CVE record was published on 2026-04-06T13:17:18.417Z. Users should verify affected deployments and review vendor guidance.

Vendor
Mattermost
Product
Legal Hold
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-08-06
Advisory published
2026-04-06
Advisory updated
2026-08-06

Who should care

Users of Mattermost Plugin Legal Hold versions <=1.1.4, administrators responsible for plugin management and security, security teams monitoring for potential unauthorized data access, and operators managing affected deployments should be aware of this vulnerability and take necessary actions to protect their environments. This includes reviewing and restricting API requests, implementing compensating controls, and monitoring for suspicious activity.

Technical summary

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP, allowing authenticated attackers to access, create, download, and delete legal hold data via crafted API requests. Defenders should focus on restricting API requests and implementing compensating controls. The vulnerability affects Mattermost Plugin Legal Hold deployments.

Defensive priority

Authenticated attackers can access, create, download, and delete legal hold data via crafted API requests due to a failed authorization check in Mattermost Plugin Legal Hold versions <=1.1.4.

Recommended defensive actions

  • Verify Mattermost Plugin Legal Hold version and upgrade to 1.1.5 or later if possible
  • Review and restrict API requests to the plugin's endpoints
  • Monitor for suspicious activity related to legal hold data
  • Implement compensating controls for authentication and authorization
  • Review vendor advisories for additional guidance
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE-2026-3524 record indicates Mattermost Plugin Legal Hold versions <=1.1.4 are vulnerable due to a failed authorization check. Verification is recommended via vendor advisories and inventory checks. Evidence is limited, and defenders should verify affected deployments, review vendor guidance, and monitor for suspicious activity related to legal hold data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-3524 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-3524

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-3524 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3524

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.