AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-9816

HIGH · CVSS 8.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to inadequate server-side validation of BoardMember.Scheme fields, allowing unauthorized board editors or non-guest team members to escalate privileges by granting board admin rights to arbitrary users. This vulnerability poses a significant risk of unauthorized access and potential data breaches within collaborative environments. Organizations using affected Mattermost versions should prioritize remediation to mitigate the risk of privilege escalation and protect sensitive information.

CVE
CVE-2026-9816
Severity
HIGH
CVSS
8.3
EPSS
0.24%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import.. Mattermost Advisory ID: MMSA-2026-00685

Related CVEs

Other vulnerabilities affecting the same vendor(s)