Impact
The vulnerability allows an authenticated non‑guest team member to create boards because the import process does not enforce the usual board‑creation permissions, letting users bypass restrictions set by administrators and create Open or Private boards. This is a privilege‑escalation problem that can result in unauthorized board disclosure or modification, potentially compromising team collaboration data.
Affected Systems
The issue affects Mattermost versions 11.9.x up to and including 11.9.0, 11.8.x up to 11.8.4, 11.7.x up to 11.7.7, and 10.11.x up to 10.11.22. All Mattermost installations running any of these versions are vulnerable until they are patched with the recommended updates.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, but EPSS data is not available and the vulnerability is not listed in KEV, suggesting it is not widely exploited. The likely attack path requires an authenticated member who is not a guest; such a user can craft a .boardarchive file and import it. Once authenticated, they can create boards. Remediation is available via a patch, but until updated the threat remains to stakeholders with normal team access.
OpenCVE Enrichment