Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 11.9.0, 11.8.3, 11.7.7, 10.11.22 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Mon, 17 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 17 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697 | |
| Title | Channel member roles accept out-of-scope roles | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-08-17T15:37:17.479Z
Reserved: 2026-07-17T09:45:24.899Z
Link: CVE-2026-16048
No data.
Status : Received
Published: 2026-08-17T15:16:54.310
Modified: 2026-08-17T15:16:54.310
Link: CVE-2026-16048
No data.
OpenCVE Enrichment
Updated: 2026-08-17T15:30:06Z
-
CWE-863
Incorrect Authorization