Impact
Mattermost releases prior to 11.7.7, 11.8.4, and 10.11.22 fail to validate BoardMember.Scheme* fields on the server when inserting or importing archive data. This oversight allows a user with board‑editor permissions or a non‑guest team member to use the POST /api/v2/boards/{boardID}/members or POST /api/v2/teams/{teamID}/archive/import endpoints to grant arbitrary board‑admin privileges to any user. The flaw violates access‑control checks (CWE‑863) and enables an attacker to elevate rights within a board or team, compromising confidentiality and integrity for those collaborators.
Affected Systems
The vulnerability affects Mattermost messaging platform installations. Versions 10.11.x up to 10.11.21, 11.7.x up to 11.7.6, and 11.8.x up to 11.8.3 are susceptible, regardless of deployment size or configuration.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. EPSS is not reported, and the flaw is not listed in CISA KEV. The attack vector requires an authenticated user with board‑editor or non‑guest team permissions; the attacker can craft POST requests to the affected API paths. Once exploited, the attacker gains full administrative control over a board or team, and the exploitation process is straightforward for anyone who can reach the API.
OpenCVE Enrichment