CVE-2026-3524Disclosure(mattermost / legal_hold)

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • legal_hold

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
legal_hold

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-06: 5Technical Details · 2026-04-06: 504-06
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3524: HIGH] Mattermost Plugin Legal Hold versions &lt;=1.1.4 vulnerable to authenticated exploitation, enabling unauthorized access, creation, download, and deletion of legal hold data. Issue tracked in...#cve,CVE-2026-3524,#cybersecurity https://cvefind.com/CVE-2026-3524

    Post summary

    The post announces CVE-2026-3524 as a high‑severity flaw in Mattermost Plugin Legal Hold, detailing that authenticated users can access, modify, and delete legal hold data for versions <=1.1.4.

    0000039
    619 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3524 Unauthorized Legal Hold Data Access in Mattermost Plugin Legal Hold Versions 1.1.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3524

    Post summary

    Vulmon lists CVE-2026-3524 as an unauthorized legal hold data access vulnerability affecting Mattermost Plugin Legal Hold v1.1.4, with no PoC or exploit details disclosed.

    0000055
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3524 - High Mattermost Plugin Legal Hold versions &amp;lt;=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, downl... https://www.thehackerwire.com/vulnerability/CVE-2026-3524/ https://t.co/zFXqrcK5bm

    Post summary

    The post announces the CVE‑2026‑3524 vulnerability in Mattermost Plugin Legal Hold (versions ≤1.1.4), describing an authorization bypass that lets authenticated users perform privileged actions.

    0000067
    164 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3524 Mattermost Plugin Legal Hold versions &lt;=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to … https://www.cve.org/CVERecord?id=CVE-2026-3524 ----- Traducción: CVE-2026-3524 Mat… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑3524, detailing an authentication‑bypass flaw in Mattermost Plugin Legal Hold that lets authenticated attackers continue processing requests; it provides the vulnerability description but no exploit, patch, or PoC.

    0000035
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3524 Mattermost Plugin Legal Hold versions &lt;=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to … https://www.cve.org/CVERecord?id=CVE-2026-3524

    Post summary

    The text briefly describes CVE-2026-3524 as a Mattermost Plugin Legal Hold flaw that lets authenticated attackers bypass authorization checks, linking to the CVE record but providing no PoC, exploit, patch, or evidence of active exploitation.

    00000436
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmattermostlegal_hold-mattermost-

Explore more