CVE-2026-6961
published 2026-06-12CVE-2026-6961: Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from…
PriorityP348high7.6CVSS 3.1
AVNACLPRHUINSCCNIHAL
EPSS
0.30%
22.8th percentile
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary locations within the target server's filestore via path traversal sequences in the filename field.. Mattermost Advisory ID: MMSA-2026-00661
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 10.11.0 < 10.11.17 | 10.11.17 |
| github.com | mattermost_mattermost-server | >= 11.5.0 < 11.5.5 | 11.5.5 |
| github.com | mattermost_mattermost-server | >= 11.6.0 < 11.6.1 | 11.6.1 |
| github.com | mattermost_mattermost_server_v8 | >= 8.0.0-20250731163400-5b955468ea1e < 8.0.0-20260423180926-c021eeaff8f0 | 8.0.0-20260423180926-c021eeaff8f0 |
| mattermost | mattermost | 10.11.0 – 10.11.15 | — |
| mattermost | mattermost | 11.5.0 – 11.5.4 | — |
| mattermost | mattermost | 11.6.0 – 11.6.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file syn
ghsa_unreviewed·2026-06-12
CVE-2026-6961 [HIGH] CWE-22 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file syn
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary locations within the target server's filestore via path traversal sequences in the filename field.. Mattermost Advisory ID: MMSA-2026-00661
VulDB
Mattermost up to 11.6.x Shared Channel filename path traversal
vuldb·2026-06-12·CVSS 7.6
CVE-2026-6961 [HIGH] Mattermost up to 11.6.x Shared Channel filename path traversal
A vulnerability has been found in Mattermost up to 10.11.15/10.11.16/11.5.4/11.6.1/11.6.x and classified as critical. This affects an unknown function of the component Shared Channel Handler. Performing a manipulation of the argument filename results in path traversal.
This vulnerability was named CVE-2026-6961. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
ghsa·2026-06-12
CVE-2026-6961 [HIGH] CWE-22 Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary locations within the target server's filestore via path traversal sequences in the filename field. Mattermost Advisory ID: MMSA-2026-00661
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-12
Published