CyberRota Analysis
AI-GeneratedMattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 are vulnerable due to insufficient enforcement of PermissionManageBoardRoles on the channelId field in the batch endpoint, allowing authenticated board editors to manipulate board-channel associations through crafted PATCH requests. This could lead to unauthorized access and modification of board content, potentially compromising sensitive information. Organizations using affected Mattermost versions should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686
Related CVEs
Other vulnerabilities affecting the same vendor(s)