Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import.. Mattermost Advisory ID: MMSA-2026-00685
Published: 2026-08-17
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost releases prior to 11.7.7, 11.8.4, and 10.11.22 fail to validate BoardMember.Scheme* fields on the server when inserting or importing archive data. This oversight allows a user with board‑editor permissions or a non‑guest team member to use the POST /api/v2/boards/{boardID}/members or POST /api/v2/teams/{teamID}/archive/import endpoints to grant arbitrary board‑admin privileges to any user. The flaw violates access‑control checks (CWE‑863) and enables an attacker to elevate rights within a board or team, compromising confidentiality and integrity for those collaborators.

Affected Systems

The vulnerability affects Mattermost messaging platform installations. Versions 10.11.x up to 10.11.21, 11.7.x up to 11.7.6, and 11.8.x up to 11.8.3 are susceptible, regardless of deployment size or configuration.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity. EPSS is not reported, and the flaw is not listed in CISA KEV. The attack vector requires an authenticated user with board‑editor or non‑guest team permissions; the attacker can craft POST requests to the affected API paths. Once exploited, the attacker gains full administrative control over a board or team, and the exploitation process is straightforward for anyone who can reach the API.

Generated by OpenCVE AI on August 18, 2026 at 00:07 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 11.7.7, 10.11.22, 11.8.4 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to 11.9.0, 11.7.7, 10.11.22, 11.8.4 or later.
  • Verify that the API endpoints POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import now reject attempts to assign admin rights to arbitrary users.
  • Restrict board‑editor permissions to trusted users until the patch is applied.

Generated by OpenCVE AI on August 18, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 17 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import.. Mattermost Advisory ID: MMSA-2026-00685
Title Insufficient server-side validation of board member role fields permits privilege escalation
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-17T22:05:24.910Z

Reserved: 2026-05-28T09:54:00.723Z

Link: CVE-2026-9816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:27.217

Modified: 2026-08-17T22:17:27.217

Link: CVE-2026-9816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:15:03Z

Weaknesses