Impact
The Boards plugin for Mattermost fails to reconcile SchemeAdmin flags when a user is demoted to System Guest, allowing the user to retain Board Admin privileges. This flaw permits the user to execute admin‑only operations through the Boards REST API or user interface, enabling unauthorized privilege escalation within the Mattermost platform.
Affected Systems
Affected versions are Mattermost 10.11.x up to 10.11.21, 11.7.x up to 11.7.6, and 11.8.x up to 11.8.3. The issue arises in the Boards plugin component of Mattermost and involves the core platform’s role‑management logic.
Risk and Exploitability
With a CVSS score of 6.3 the vulnerability is of moderate severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via the Boards REST API or UI, allowing a demoted user to perform administrative actions remotely if the Mattermost instance is reachable over the network.
OpenCVE Enrichment