CVEFind.com@CveFindComDisclosure
The post announces CVE-2026-3524 as a high‑severity flaw in Mattermost Plugin Legal Hold, detailing that authenticated users can access, modify, and delete legal hold data for versions <=1.1.4.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
Vulmon lists CVE-2026-3524 as an unauthorized legal hold data access vulnerability affecting Mattermost Plugin Legal Hold v1.1.4, with no PoC or exploit details disclosed.
The Hacker Wire@TheHackerWireDisclosure
The post announces the CVE‑2026‑3524 vulnerability in Mattermost Plugin Legal Hold (versions ≤1.1.4), describing an authorization bypass that lets authenticated users perform privileged actions.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑3524, detailing an authentication‑bypass flaw in Mattermost Plugin Legal Hold that lets authenticated attackers continue processing requests; it provides the vulnerability description but no exploit, patch, or PoC.
CVE@CVEnewDisclosure
The text briefly describes CVE-2026-3524 as a Mattermost Plugin Legal Hold flaw that lets authenticated attackers bypass authorization checks, linking to the CVE record but providing no PoC, exploit, patch, or evidence of active exploitation.