Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00672
Published: 2026-08-17
Score: 3.9 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost versions 11.7.x through 11.7.6 and 10.11.x through 10.11.21 allow a board member to create a specially crafted .boardarchive file that grants guest users Board Admin privileges. This flaw enables the elevation of a guest account to a board‑level administrator, providing the attacker with full control over board settings, data, and potentially the ability to perform further malicious actions. The vulnerability corresponds to CWE‑863: Privilege Control Weakness.

Affected Systems

The affected products are Mattermost Boards in versions 11.7.0‑11.7.6 and 10.11.0‑10.11.21. The recommended fix is to update to 11.9.0, 11.7.7, 10.11.22 or any later release that contains the patch.

Risk and Exploitability

The CVSS score is 3.9, indicating low severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, suggesting a limited presence of publicly used exploit code. The attack requires a board member or an authorized user who can upload a .boardarchive file; once an attacker supplies a crafted file, the system mistakenly grants Board Admin rights to a guest account. The vulnerability can be exploited through normal import functionality and does not require remote network access or elevated system privileges beyond those needed to upload a board archive.

Generated by OpenCVE AI on August 17, 2026 at 15:16 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 11.7.7, 10.11.22 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to a fixed version (11.9.0, 11.7.7, 10.11.22 or later).
  • Reconfigure role assignments so that guest users cannot receive Board Admin privileges during import operations.
  • If an immediate upgrade is not possible, disable the .boardarchive import capability for guest users until the patch is applied.

Generated by OpenCVE AI on August 17, 2026 at 15:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 17 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00672
Title Insufficient validation of guest board admin privileges on archive import
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-17T15:25:51.740Z

Reserved: 2026-07-17T09:40:22.350Z

Link: CVE-2026-16044

cve-icon Vulnrichment

Updated: 2026-08-17T15:25:47.520Z

cve-icon NVD

Status : Received

Published: 2026-08-17T15:16:53.857

Modified: 2026-08-17T16:16:50.460

Link: CVE-2026-16044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:30:06Z

Weaknesses