Description
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665
Published: 2026-06-12
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because the Group Syncable Link and Patch endpoints in Mattermost fail to enforce role‑management authorization when the scheme_admin flag is set. An authenticated user who has permission to manage group links can craft API requests to set scheme_admin for a group, thereby granting themselves and all members of that group team or channel admin status. This creates a privilege escalation path that grants full administrative control within affected teams or channels. The weakness is identified as CWE‑863, which involves failure to check permissions.

Affected Systems

Mattermost versions 10.11.x up to 10.11.15, 10.11.16; 11.5.x up to 11.5.4; and 11.6.x up to 11.6.1 are vulnerable. All vulnerability is confined to the Mattermost product; affected users are those with group‑link permissions on these versions.

Risk and Exploitability

The CVSS score of 8.8 classifies this issue as high severity. Exploit probability is not available, but the vulnerability is not listed in CISA KEV. The attack vector is likely via the API: an authenticated user with group‑link permissions must send crafted HTTP requests to set the scheme_admin flag. Therefore, the risk is significant for environments where such permissions are assigned to many users, as a single compromised account could elevate a large number of users to administrative roles.

Generated by OpenCVE AI on June 12, 2026 at 18:21 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.7.0, 11.6.2, 11.5.5, 10.11.16, 10.11.17 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to a patched version (11.7.0, 11.6.2, 11.5.5, 10.11.16, 10.11.17 or higher).
  • Restrict the Group Link permission to trusted users or remove the ability to set scheme_admin for non‑administrative accounts.
  • Enforce role‑management checks for scheme_admin changes by verifying that only administrator‑level users can modify this flag and reviewing API logs for unauthorized changes.

Generated by OpenCVE AI on June 12, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 12 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Fri, 12 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665
Title Mattermost group syncable endpoints allow privilege escalation via scheme_admin
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-06-13T03:56:08.889Z

Reserved: 2026-04-29T09:18:29.691Z

Link: CVE-2026-7387

cve-icon Vulnrichment

Updated: 2026-06-12T17:18:05.747Z

cve-icon NVD

Status : Received

Published: 2026-06-12T17:16:27.653

Modified: 2026-06-12T17:16:27.653

Link: CVE-2026-7387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T18:30:32Z

Weaknesses