Impact
Mattermost versions before 11.9.0 (11.8.x <= 11.8.2), 11.7.x <= 11.7.6, and 10.11.x <= 10.11.21 allow a channel administrator to assign roles that are not limited to the channel scope through the channel member roles API. This failure to enforce role scope is a CWE‑863 authorization control weakness that can let an authorized administrator grant themselves or others permissions that should be unavailable at the channel level, effectively escalating privileges within the channel.
Affected Systems
Mattermost Community Edition 10.11.0 through 10.11.21, 11.7.0 through 11.7.6, and 11.8.0 through 11.8.2 are affected. All releases that include the channel member roles API contain the vulnerability and require update.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity risk. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting widespread exploitation has not been observed. However, because the flaw can be exercised by any user who has channel administrator privileges, it is likely to be used by insiders or compromised accounts. Exploitation requires authenticated access to the API and does not rely on network exploits outside the normal administrative environment.
OpenCVE Enrichment