Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00712
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized board creation due to permission bypass
Action: Assess Impact
AI Analysis

Impact

The vulnerability allows an authenticated non‑guest team member to create boards because the import process does not enforce the usual board‑creation permissions, letting users bypass restrictions set by administrators and create Open or Private boards. This is a privilege‑escalation problem that can result in unauthorized board disclosure or modification, potentially compromising team collaboration data.

Affected Systems

The issue affects Mattermost versions 11.9.x up to and including 11.9.0, 11.8.x up to 11.8.4, 11.7.x up to 11.7.7, and 10.11.x up to 10.11.22. All Mattermost installations running any of these versions are vulnerable until they are patched with the recommended updates.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, but EPSS data is not available and the vulnerability is not listed in KEV, suggesting it is not widely exploited. The likely attack path requires an authenticated member who is not a guest; such a user can craft a .boardarchive file and import it. Once authenticated, they can create boards. Remediation is available via a patch, but until updated the threat remains to stakeholders with normal team access.

Generated by OpenCVE AI on September 15, 2026 at 14:40 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to a patched version: 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or newer.
  • Disable or restrict board archive import for non‑guest users by modifying the configuration to prevent the import endpoint from processing such files.
  • Enforce and audit board creation events to detect any unauthorized activity.

Generated by OpenCVE AI on September 15, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00712
Title Board archive import bypasses team board creation permissions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T19:36:08.766Z

Reserved: 2026-06-30T16:00:56.371Z

Link: CVE-2026-14259

cve-icon Vulnrichment

Updated: 2026-09-14T19:36:03.427Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:03.307

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-14259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:45:11Z

Weaknesses