Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686
Published: 2026-08-17
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates in the Mattermost Boards plugin, where the plugin’s batch endpoint fails to enforce the PermissionManageBoardRoles privilege on the channelId parameter. As a result, any authenticated board editor can send a crafted PATCH request to link a board they are allowed to edit to any channel of their choice. This flaw allows a board editor to expose board contents to unintended audiences, effectively bypassing intended access controls and potentially leaking sensitive information that should be restricted within the original channel scope. The weakness is classified as a permissions logic error (CWE‑863).

Affected Systems

Affected versions of the Mattermost product include 11.7.x through 11.7.6, 10.11.x through 10.11.21, and 11.8.x through 11.8.3. The advisory applies to the core Mattermost application and its Boards plugin, as documented by the Mattermost CNA.

Risk and Exploitability

The CVSS score of 6.5 marks this as a moderate severity flaw. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with board editor rights, so the attack vector is internal or delegated through compromised credentials. A malicious editor can leverage a crafted PATCH request to the batch endpoint to re‑link a board to any channel, thereby exposing confidential board data to unauthorized viewers. The exploit is straightforward for anyone possessing necessary permissions, but it does not allow arbitrary remote code execution or system compromise.

Generated by OpenCVE AI on August 18, 2026 at 00:07 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 11.7.7, 10.11.22, 11.8.4 or higher.


OpenCVE Recommended Actions

  • Apply the Mattermost update to 11.9.0 or later, 11.7.7 or later, 10.11.22 or later, or 11.8.4 or later to restore proper permission enforcement.
  • After updating, audit existing board‑channel links to detect any boards that may have been inadvertently exposed to channels they should not appear in.
  • If board editing is required within your organization, restrict the PermissionManageBoardRoles privilege to trusted users and review channel membership rules to limit unintended board exposure.

Generated by OpenCVE AI on August 18, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 17 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686
Title Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose boards to arbitrary channels
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-17T22:06:26.318Z

Reserved: 2026-05-28T15:58:29.723Z

Link: CVE-2026-9859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:27.343

Modified: 2026-08-17T22:17:27.343

Link: CVE-2026-9859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:15:03Z

Weaknesses