SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14259

MEDIUM · CVSS 4.3

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Mattermost versions 11.9.0 and earlier, as well as 11.8.4, 11.7.7, and 10.11.22, are vulnerable due to inadequate enforcement of board creation permissions during the import of archive files, allowing authenticated non-guest team members to bypass administrator restrictions. This could lead to unauthorized creation of Open or Private boards, potentially compromising sensitive team discussions and project management. Organizations using affected Mattermost versions, especially those with strict access controls, should prioritize applying the relevant patches to mitigate this risk.

CVE
CVE-2026-14259
Severity
MEDIUM
CVSS
4.3
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00712