CyberRota Analysis
AI-GeneratedCertain versions of Mattermost are vulnerable due to improper handling of user role changes, allowing demoted users to retain Board Admin privileges and perform administrative actions through the Boards REST API or UI. This flaw could lead to unauthorized access and manipulation of sensitive board data. Organizations using affected Mattermost versions should prioritize patching to mitigate potential risks associated with unauthorized administrative capabilities.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations via the Boards REST API or UI.. Mattermost Advisory ID: MMSA-2026-00691
Related CVEs
Other vulnerabilities affecting the same vendor(s)