AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-16047

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 are vulnerable due to inadequate validation of user access rights to channels, enabling authenticated attackers to expose the membership of private channels by manipulating board links. This vulnerability could lead to unauthorized disclosure of sensitive team information. Organizations using these versions should prioritize patching to mitigate the risk of information leakage.

CVE
CVE-2026-16047
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a board to it, which allows an authenticated attacker to discover the membership of private channels on the same team via creating, patching, importing, or bulk-creating boards with an arbitrary channelId. Mattermost Advisory ID: MMSA-2026-00674

Related CVEs

Other vulnerabilities affecting the same vendor(s)