Impact
The vulnerability is caused by inconsistent enforcement of the board‑creation permission, allowing any authenticated user to create boards through the board duplicate, boards‑and‑blocks, and archive‑import endpoints. The result is that an attacker without the proper rights can create and populate boards, potentially exposing sensitive messages or misusing the platform for malicious content. This flaw does not grant direct code execution or database compromise, but it does enable unauthorized data creation and could serve as a foothold for further exploitation.
Affected Systems
Mattermost: versions 11.9.x and earlier (≤11.9.0), 11.8.x and earlier (≤11.8.4), 11.7.x and earlier (≤11.7.7), and 10.11.x and earlier (≤10.11.22).
Risk and Exploitability
The CVSS v3.1 base score of 4.3 indicates medium severity. EPSS is not available, so the current likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through an authenticated user session; the attacker must log into Mattermost with any user account but does not need administrative privileges. Since the flaw allows creation of boards but not necessarily arbitrary data, the impact is limited to unauthorized data insertion and potential disruption of team collaboration.
OpenCVE Enrichment