SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16044

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 are vulnerable due to improper access controls that allow guest users to be granted Board Admin privileges through the import of a specially crafted .boardarchive file. This vulnerability can lead to unauthorized access and potential manipulation of board content, posing a risk to the integrity of board management. Organizations using these versions should prioritize patching to mitigate the risk of privilege escalation.

CVE
CVE-2026-16044
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00672

Related CVEs

Other vulnerabilities affecting the same vendor(s)