CVE-2026-3112
vulnerability analysis and mitigation

Overview

CVE-2026-3112 is a path traversal vulnerability in Mattermost Server that allows authenticated system administrators to read arbitrary files from the host system via a maliciously crafted AdvancedLoggingJSON configuration during support packet generation. It is tracked under Mattermost Advisory ID MMSA-2025-00562 and affects versions 11.4.x ≤ 11.4.0, 11.3.x ≤ 11.3.1, 11.2.x ≤ 11.2.3, and 10.11.x ≤ 10.11.11. The vulnerability was disclosed on March 26, 2026, and carries a CVSS v3.1 base score of 4.9 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is insufficient validation of file target paths in Mattermost's Advanced Logging subsystem, classified as CWE-22 (Path Traversal) and CWE-73 (External Control of File Name or Path). An attacker with system administrator privileges can supply a malicious AdvancedLoggingJSON configuration that specifies arbitrary file paths on the host, which are then read and included in the generated support packet without proper sanitization or restriction to an allowed directory. Exploitation requires network access and high-privilege credentials but no user interaction, making it a server-side information disclosure attack (Red Hat Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows a privileged system administrator to read arbitrary files from the underlying host operating system — including sensitive files such as /etc/passwd, private keys, configuration files containing credentials, or other confidential data outside the intended application scope. The confidentiality impact is rated High, while integrity and availability are unaffected. Although the attacker must already hold system administrator privileges within Mattermost, this vulnerability could enable privilege escalation beyond the application boundary or facilitate lateral movement by exposing host-level secrets (Red Hat Advisory).

Exploitation steps

  1. Gain System Administrator Access: Authenticate to the Mattermost instance using a system administrator account (obtained via credential theft, phishing, or insider access).
  2. Craft Malicious AdvancedLoggingJSON Configuration: Construct a logging configuration JSON that specifies a file target path pointing to a sensitive host file (e.g., /etc/shadow, /etc/passwd, or application secrets) instead of a legitimate log file path.
  3. Apply the Configuration: Submit the malicious AdvancedLoggingJSON configuration through the Mattermost system console or API endpoint responsible for advanced logging settings.
  4. Trigger Support Packet Generation: Initiate a support packet generation action, which causes Mattermost to read the specified file path without adequate path validation.
  5. Retrieve Sensitive File Contents: Download or inspect the generated support packet to extract the contents of the arbitrary host file that was included due to the path traversal (Red Hat Bugzilla, Red Hat Advisory).

Indicators of compromise

  • Logs: Mattermost application logs showing support packet generation events initiated by administrator accounts, particularly with unusual or unexpected timing; log entries referencing file paths outside the standard Mattermost data directory.
  • Configuration: Changes to the AdvancedLoggingJSON system configuration containing file target paths referencing sensitive OS-level files (e.g., /etc/, /root/, /home/, /var/, key/certificate directories).
  • File System: Unexpected access timestamps on sensitive host files (e.g., /etc/passwd, /etc/shadow, SSH private keys) coinciding with support packet generation events.
  • Network: Downloads of support packet archives from the Mattermost admin interface by administrator accounts, especially from unfamiliar IP addresses or at unusual times.

Mitigation and workarounds

Organizations should upgrade Mattermost Server to the patched versions: 11.4.1, 11.3.2, 11.2.4, or 10.11.12, depending on the currently deployed branch. As an interim measure, restrict system administrator access to only trusted personnel and audit recent support packet generation events for suspicious AdvancedLoggingJSON configurations. Review Mattermost access logs for any unauthorized file access patterns that may indicate prior exploitation attempts (Mattermost Security, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management