CVE-2026-9859
Received Received - Intake

Permission Bypass in Mattermost Board Editor

Vulnerability report for CVE-2026-9859, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mattermost 11.7 to 11.7.6 (inc)
mattermost 10.11 to 10.11.21 (inc)
mattermost 11.8 to 11.8.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mattermost versions between 11.7.0 and 11.7.6, 10.11.0 and 10.11.21, and 11.8.0 and 11.8.3 have a flaw where the system does not properly enforce the PermissionManageBoardRoles permission on the channelId field in the batch endpoint. This allows an authenticated user with board editor privileges to relink a board they can edit to any channel by sending a specially crafted PATCH request.

Detection Guidance

Detecting this vulnerability requires checking Mattermost server logs for suspicious PATCH requests to the batch endpoint with modified channelId fields. Monitor for unauthorized board relinking attempts or unexpected channel changes. No specific commands are provided in the context.

Impact Analysis

An attacker with board editor access could move sensitive boards to unauthorized channels, potentially exposing restricted information to unintended users. This could lead to data leaks or unauthorized access to board content.

Compliance Impact

This vulnerability could lead to unauthorized access or disclosure of sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using affected Mattermost versions may face compliance violations if boards containing regulated data are exposed.

Mitigation Strategies

Upgrade Mattermost to a patched version (11.7.7+, 10.11.22+, or 11.8.4+). If immediate upgrade is not possible, restrict board editor permissions and monitor for unauthorized board relinking attempts via server logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9859. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart