What is CVE-2026-7521?
This vulnerability exists due to improper file deletion path validation in Mattermost. An admin with SAML system-console write permissions can delete arbitrary files outside the config directory via the remove file endpoint. It is strongly recommended to upgrade affected Mattermost versions to the latest security patch immediately.
Azərbaycanca: Bu boşluq Mattermost-un fayl silmə əməliyyatında yol doğrulamasının olmaması səbəbindən yaranır. SAML sistem konsoluna yazma icazəsi olan admin config qovluğundan kənarda ixtiyari faylları silə bilər. Mattermost-un təsirlənmiş versiyalarını dərhal ən son təhlükəsizlik yeniləməsinə qədər yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
What operation can an admin with SAML system-console write permissions perform in Mattermost?
An admin with SAML system-console write permissions can delete arbitrary files outside the config directory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.