CVE-2026-9816
- EPSS 0.25%
- Veröffentlicht 17.08.2026 22:05:24
- Zuletzt bearbeitet 19.08.2026 13:29:28
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitr...
CVE-2026-10080
- EPSS 0.29%
- Veröffentlicht 17.08.2026 22:04:30
- Zuletzt bearbeitet 18.08.2026 16:19:17
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards users via a custom_focalboard_SU...
CVE-2026-10527
- EPSS 0.15%
- Veröffentlicht 17.08.2026 14:37:46
- Zuletzt bearbeitet 18.08.2026 20:21:57
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations...
CVE-2026-15754
- EPSS 0.15%
- Veröffentlicht 17.08.2026 14:36:56
- Zuletzt bearbeitet 18.08.2026 20:24:58
Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ...
CVE-2026-16044
- EPSS 0.17%
- Veröffentlicht 17.08.2026 14:26:52
- Zuletzt bearbeitet 18.08.2026 20:27:55
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .board...
CVE-2026-16045
- EPSS 0.2%
- Veröffentlicht 17.08.2026 14:26:22
- Zuletzt bearbeitet 18.08.2026 20:32:18
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the...
CVE-2026-16047
- EPSS 0.16%
- Veröffentlicht 17.08.2026 14:25:08
- Zuletzt bearbeitet 18.08.2026 20:41:36
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a board to it, which allows an authenticated attacker to discover the membership of private channels ...
CVE-2026-16046
- EPSS 0.15%
- Veröffentlicht 17.08.2026 14:24:14
- Zuletzt bearbeitet 18.08.2026 20:34:52
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participa...
CVE-2026-16048
- EPSS 0.15%
- Veröffentlicht 17.08.2026 14:22:43
- Zuletzt bearbeitet 18.08.2026 20:42:05
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member rol...
CVE-2026-14298
- EPSS 0.24%
- Veröffentlicht 13.08.2026 08:03:00
- Zuletzt bearbeitet 14.09.2026 11:17:03
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated use...