CVE-2026-6961 | Mattermost up to 11.6.x Shared Channel filename path traversal (EUVD-2026-36504)
A vulnerability has been found in Mattermost up to 10.11.15/10.11.16/11.5.4/11.6.1/11.6.x and classified as critical. This affects an unknown function of the component Shared Channel Handler. Performing a manipulation of the argument filename results in path traversal.
This vulnerability was named CVE-2026-6961. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.