AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-9859

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 are vulnerable due to insufficient enforcement of PermissionManageBoardRoles on the channelId field in the batch endpoint, allowing authenticated board editors to manipulate board-channel associations through crafted PATCH requests. This could lead to unauthorized access and modification of board content, potentially compromising sensitive information. Organizations using affected Mattermost versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-9859
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686

Related CVEs

Other vulnerabilities affecting the same vendor(s)