CyberRota Analysis
AI-GeneratedMattermost versions 11.9.0 and earlier, as well as 11.8.4, 11.7.7, and 10.11.22, are vulnerable due to inadequate enforcement of board creation permissions during the import of archive files, allowing authenticated non-guest team members to bypass administrator restrictions. This could lead to unauthorized creation of Open or Private boards, potentially compromising sensitive team discussions and project management. Organizations using affected Mattermost versions, especially those with strict access controls, should prioritize applying the relevant patches to mitigate this risk.
Original NVD Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00712