CVE-2026-16047
Received Received - Intake

Information Disclosure in Mattermost via Board Channel Linking

Vulnerability report for CVE-2026-16047, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a board to it, which allows an authenticated attacker to discover the membership of private channels on the same team via creating, patching, importing, or bulk-creating boards with an arbitrary channelId. Mattermost Advisory ID: MMSA-2026-00674

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.7.6 (inc)
mattermost mattermost to 10.11.21 (inc)
mattermost mattermost to 11.8.3 (inc)
mattermost 11.7 to 11.7.6 (inc)
mattermost 10.11 to 10.11.21 (inc)
mattermost 11.8 to 11.8.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mattermost versions between 11.7.0 and 11.7.6, 10.11.0 and 10.11.21, and 11.8.0 and 11.8.3 have a flaw where they do not check if users have permission to access a channel before linking a board to it. This allows attackers with valid accounts to discover private channel memberships by manipulating boards.

Detection Guidance

This vulnerability requires checking Mattermost server logs and configurations for unauthorized board-channel link attempts. Look for API calls to /boards/boards, /boards/boards/patch, or /boards/boards/import with arbitrary channelId values in private channels. Review logs for actions by non-admin users creating or modifying boards linked to private channels they shouldn't access.

Impact Analysis

An authenticated attacker could identify members of private channels you belong to, potentially exposing sensitive team communications or user information. This could lead to privacy breaches or targeted phishing attacks against those users.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR or HIPAA by exposing private channel memberships, which may contain personal or health data. Organizations using affected versions may face compliance risks and potential regulatory penalties.

Mitigation Strategies

Update Mattermost to a version that fixes the vulnerability. Specifically, upgrade to versions 11.7.7, 10.11.22, or 11.8.4 or later to address the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16047. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart