CVE-2026-3524 - Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission Check
CVE ID :CVE-2026-3524
Published : April 6, 2026, 12:06 p.m. | 1 hour, 1 minute ago
Description :Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 6, 2026, 12:06 p.m. | 1 hour, 1 minute ago
Description :Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...