Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost Advisory ID: MMSA-2026-00593

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update Mattermost to versions 11.5.0, 11.4.1, 11.3.2, 11.2.4, 10.11.12 or higher.


Workaround

No workaround given by the vendor.

References
History

Thu, 26 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost Advisory ID: MMSA-2026-00593
Title mmctl export download command doesn’t restrict permissions to created file to file owner
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-03-26T17:51:15.160Z

Reserved: 2026-02-24T10:59:55.681Z

Link: CVE-2026-3113

cve-icon Vulnrichment

Updated: 2026-03-26T17:47:41.119Z

cve-icon NVD

Status : Received

Published: 2026-03-26T17:16:42.307

Modified: 2026-03-26T17:16:42.307

Link: CVE-2026-3113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses