Impact
Mattermost versions 11.7.x through 11.7.6 and 10.11.x through 10.11.21 allow a board member to create a specially crafted .boardarchive file that grants guest users Board Admin privileges. This flaw enables the elevation of a guest account to a board‑level administrator, providing the attacker with full control over board settings, data, and potentially the ability to perform further malicious actions. The vulnerability corresponds to CWE‑863: Privilege Control Weakness.
Affected Systems
The affected products are Mattermost Boards in versions 11.7.0‑11.7.6 and 10.11.0‑10.11.21. The recommended fix is to update to 11.9.0, 11.7.7, 10.11.22 or any later release that contains the patch.
Risk and Exploitability
The CVSS score is 3.9, indicating low severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, suggesting a limited presence of publicly used exploit code. The attack requires a board member or an authorized user who can upload a .boardarchive file; once an attacker supplies a crafted file, the system mistakenly grants Board Admin rights to a guest account. The vulnerability can be exploited through normal import functionality and does not require remote network access or elevated system privileges beyond those needed to upload a board archive.
OpenCVE Enrichment