PatchSiren cyber security CVE debrief
CVE-2026-4858 Mattermost CVE debrief
CVE-2026-4858 is a Mattermost path traversal issue in integration action URL handling. According to the published description, a malicious authenticated user can bypass URL checks and use path traversal to call arbitrary APIs with the system admin Mattermost auth token. The issue is tracked by Mattermost as advisory MMSA-2026-00640 and is rated CVSS 8.0 (HIGH).
- Vendor
- Mattermost
- Product
- Unknown
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-07-23
Who should care
Mattermost administrators, security teams, and platform owners running affected Mattermost versions, especially environments that use integrations or action URLs and rely on system admin authentication tokens.
Technical summary
The vulnerability is described as a failure to validate integration URLs against path traversal, allowing an authenticated attacker to manipulate an integration action URL and reach arbitrary API endpoints using a system admin Mattermost auth token. NVD lists CWE-22 and the CVSS 3.1 vector AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H. Affected versions listed in the source are 11.6.x through 11.6.0, 11.5.x through 11.5.3, 11.4.x through 11.4.4, and 10.11.x through 10.11.14.
Defensive priority
High. The combination of authenticated access, token abuse, and potential cross-scope impact makes this important to remediate promptly in any exposed Mattermost deployment.
Recommended defensive actions
- Upgrade Mattermost to a fixed version referenced by the vendor advisory for MMSA-2026-00640.
- Review and restrict who can create or modify integrations and action URLs.
- Audit system admin auth token usage and rotate tokens if there is any sign of abuse.
- Check logs for unusual integration action URL activity, especially requests containing traversal-like path segments.
- Verify affected deployments against the version ranges listed in the advisory and prioritize internet-facing or highly privileged instances.
Evidence notes
All claims here are limited to the supplied CVE/NVD record and the referenced Mattermost security-updates page. The CVE description states the affected Mattermost version ranges, the authenticated-user prerequisite, the path traversal flaw in integration action URL validation, and the ability to invoke arbitrary APIs with a system admin auth token. NVD adds CWE-22 and the CVSS 3.1 vector AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H. Published and modified dates are both 2026-05-21T09:16:30.143Z.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4858 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4858
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4858 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4858
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://mattermost.com/security-updates
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.