CVE-2026-16044
Received Received - Intake

Privilege Escalation in Mattermost via Board Archive Import

Vulnerability report for CVE-2026-16044, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00672

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.7.6 (inc)
mattermost mattermost to 10.11.21 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mattermost versions between 11.7.0 and 11.7.6, and 10.11.0 and 10.11.21 have a flaw where guest users can be granted Board Admin privileges during the import of a specially crafted .boardarchive file. This occurs because the system fails to properly restrict these privileges during the import process.

Detection Guidance

To detect this vulnerability, check Mattermost server logs for unauthorized board admin privilege assignments during .boardarchive imports. Review imported archives for unexpected guest user promotions. Verify Mattermost version is not 11.7.x <= 11.7.6 or 10.11.x <= 10.11.21.

Impact Analysis

An attacker with board member access could exploit this to elevate a guest user to Board Admin, potentially gaining unauthorized control over sensitive board data and operations. This could lead to data leaks, unauthorized modifications, or disruption of board activities.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Organizations using affected versions may face regulatory penalties or reputational damage.

Mitigation Strategies

Upgrade Mattermost to versions 11.7.7 or later for 11.7.x series, or 10.11.22 or later for 10.11.x series to address the guest user privilege escalation vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16044. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart