VendorsMattermostlegal_holdany version
Vulnerabilities

Mattermost Legal Hold any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-3524
Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission Check
Published 2026-04-06 · Analyzed
8.8EPSS 0.004
CVE-2026-6957
Path traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file write.
Published 2026-05-27 · Analyzed
8.0EPSS 0.005