Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, and archive-import endpoints.. Mattermost Advisory ID: MMSA-2026-00715
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized board creation via API endpoints
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is caused by inconsistent enforcement of the board‑creation permission, allowing any authenticated user to create boards through the board duplicate, boards‑and‑blocks, and archive‑import endpoints. The result is that an attacker without the proper rights can create and populate boards, potentially exposing sensitive messages or misusing the platform for malicious content. This flaw does not grant direct code execution or database compromise, but it does enable unauthorized data creation and could serve as a foothold for further exploitation.

Affected Systems

Mattermost: versions 11.9.x and earlier (≤11.9.0), 11.8.x and earlier (≤11.8.4), 11.7.x and earlier (≤11.7.7), and 10.11.x and earlier (≤10.11.22).

Risk and Exploitability

The CVSS v3.1 base score of 4.3 indicates medium severity. EPSS is not available, so the current likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through an authenticated user session; the attacker must log into Mattermost with any user account but does not need administrative privileges. Since the flaw allows creation of boards but not necessarily arbitrary data, the impact is limited to unauthorized data insertion and potential disruption of team collaboration.

Generated by OpenCVE AI on September 15, 2026 at 14:32 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Apply the vendor provided patch by upgrading Mattermost to version 11.10.0 or any later release that supersedes the affected versions.
  • If an upgrade is not immediately possible, block or remove the board duplicate, boards‑and‑blocks, and archive‑import endpoints from public API access or restrict them to administrators only.
  • Audit your Mattermost instance for unauthorized board creation activities and monitor logs for unexpected board creation events.

Generated by OpenCVE AI on September 15, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, and archive-import endpoints.. Mattermost Advisory ID: MMSA-2026-00715
Title Inconsistent authorization checks in Mattermost Boards endpoints
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T11:19:45.837Z

Reserved: 2026-07-01T14:33:22.302Z

Link: CVE-2026-14344

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:43.505Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:03.573

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-14344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:45:11Z

Weaknesses