
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3112 is a path traversal vulnerability in Mattermost Server that allows authenticated system administrators to read arbitrary files from the host system via a maliciously crafted AdvancedLoggingJSON configuration during support packet generation. It is tracked under Mattermost Advisory ID MMSA-2025-00562 and affects versions 11.4.x ≤ 11.4.0, 11.3.x ≤ 11.3.1, 11.2.x ≤ 11.2.3, and 10.11.x ≤ 10.11.11. The vulnerability was disclosed on March 26, 2026, and carries a CVSS v3.1 base score of 4.9 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is insufficient validation of file target paths in Mattermost's Advanced Logging subsystem, classified as CWE-22 (Path Traversal) and CWE-73 (External Control of File Name or Path). An attacker with system administrator privileges can supply a malicious AdvancedLoggingJSON configuration that specifies arbitrary file paths on the host, which are then read and included in the generated support packet without proper sanitization or restriction to an allowed directory. Exploitation requires network access and high-privilege credentials but no user interaction, making it a server-side information disclosure attack (Red Hat Advisory, Red Hat Bugzilla).
Successful exploitation allows a privileged system administrator to read arbitrary files from the underlying host operating system — including sensitive files such as /etc/passwd, private keys, configuration files containing credentials, or other confidential data outside the intended application scope. The confidentiality impact is rated High, while integrity and availability are unaffected. Although the attacker must already hold system administrator privileges within Mattermost, this vulnerability could enable privilege escalation beyond the application boundary or facilitate lateral movement by exposing host-level secrets (Red Hat Advisory).
/etc/shadow, /etc/passwd, or application secrets) instead of a legitimate log file path.AdvancedLoggingJSON configuration through the Mattermost system console or API endpoint responsible for advanced logging settings.AdvancedLoggingJSON system configuration containing file target paths referencing sensitive OS-level files (e.g., /etc/, /root/, /home/, /var/, key/certificate directories)./etc/passwd, /etc/shadow, SSH private keys) coinciding with support packet generation events.Organizations should upgrade Mattermost Server to the patched versions: 11.4.1, 11.3.2, 11.2.4, or 10.11.12, depending on the currently deployed branch. As an interim measure, restrict system administrator access to only trusted personnel and audit recent support packet generation events for suspicious AdvancedLoggingJSON configurations. Review Mattermost access logs for any unauthorized file access patterns that may indicate prior exploitation attempts (Mattermost Security, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."