CVE-2026-28736: Mattermost Focalboard

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. This allows an authenticated attacker who knows a victim's fileID to read the content of the file. NOTE: Focalboard as a standalone product is not maintained and no fix will be issued.

Affected products

Published 2026-04-03. Last modified 2026-07-24.