SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-10527

MEDIUM · CVSS 6.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to improper handling of user role changes, allowing demoted users to retain Board Admin privileges and perform administrative actions through the Boards REST API or UI. This flaw could lead to unauthorized access and manipulation of sensitive board data. Organizations using affected Mattermost versions should prioritize patching to mitigate potential risks associated with unauthorized administrative capabilities.

CVE
CVE-2026-10527
Severity
MEDIUM
CVSS
6.3
EPSS
0.15%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations via the Boards REST API or UI.. Mattermost Advisory ID: MMSA-2026-00691

Related CVEs

Other vulnerabilities affecting the same vendor(s)