Description
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697
Published: 2026-08-17
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost versions before 11.9.0 (11.8.x <= 11.8.2), 11.7.x <= 11.7.6, and 10.11.x <= 10.11.21 allow a channel administrator to assign roles that are not limited to the channel scope through the channel member roles API. This failure to enforce role scope is a CWE‑863 authorization control weakness that can let an authorized administrator grant themselves or others permissions that should be unavailable at the channel level, effectively escalating privileges within the channel.

Affected Systems

Mattermost Community Edition 10.11.0 through 10.11.21, 11.7.0 through 11.7.6, and 11.8.0 through 11.8.2 are affected. All releases that include the channel member roles API contain the vulnerability and require update.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium severity risk. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting widespread exploitation has not been observed. However, because the flaw can be exercised by any user who has channel administrator privileges, it is likely to be used by insiders or compromised accounts. Exploitation requires authenticated access to the API and does not rely on network exploits outside the normal administrative environment.

Generated by OpenCVE AI on August 17, 2026 at 15:58 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 11.8.3, 11.7.7, 10.11.22 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to v11.9.0, v11.8.3, v11.7.7, or v10.11.22 or later, which includes the role‑scope validation fix.
  • If an immediate upgrade is not possible, disable or restrict the channel member roles API for channels that do not require it and monitor API usage closely.
  • Audit existing role assignments for out‑of‑scope entries, revoke any that are not confined to the channel scope, and re‑apply proper role assignment settings.

Generated by OpenCVE AI on August 17, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 17 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697
Title Channel member roles accept out-of-scope roles
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-17T15:37:17.479Z

Reserved: 2026-07-17T09:45:24.899Z

Link: CVE-2026-16048

cve-icon Vulnrichment

Updated: 2026-08-17T15:37:13.790Z

cve-icon NVD

Status : Received

Published: 2026-08-17T15:16:54.310

Modified: 2026-08-17T16:16:50.743

Link: CVE-2026-16048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T16:00:05Z

Weaknesses