CVE-2026-14259
Received Received - Intake

Mattermost Board Import Permission Bypass

Vulnerability report for CVE-2026-14259, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00712

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
mattermost 11.9 to 11.9.0 (inc)
mattermost 11.8 to 11.8.4 (inc)
mattermost 11.7 to 11.7.7 (inc)
mattermost 10.11 to 10.11.22 (inc)
mattermost mattermost to 11.9.0 (inc)
mattermost mattermost to 11.8.4 (inc)
mattermost mattermost to 11.7.7 (inc)
mattermost mattermost to 10.11.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mattermost versions between 11.9.0 and older, 11.8.4 and older, 11.7.7 and older, and 10.11.22 and older fail to enforce board creation permissions during archive file imports. This allows authenticated non-guest team members to create Open or Private boards despite admin restrictions by importing a specially crafted .boardarchive file.

Detection Guidance

This vulnerability involves improper permission enforcement during board archive imports in Mattermost. To detect it, check for unauthorized board creation events in logs, particularly for .boardarchive file imports. Review Mattermost server logs for suspicious import activities and verify board creation permissions for affected versions (11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22).

Impact Analysis

An attacker with valid but limited access could create unauthorized boards, potentially exposing sensitive data or disrupting team workflows. This bypasses intended permission controls set by administrators.

Compliance Impact

This vulnerability could lead to unauthorized data exposure or modification, violating compliance requirements for data protection such as GDPR or HIPAA. Unauthorized board creation may result in improper data handling or access controls.

Mitigation Strategies

Upgrade Mattermost to a version that fixes this issue. Specifically, update to versions beyond 11.9.0, 11.8.4, 11.7.7, or 10.11.22 depending on your current installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14259. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart