CVE-2026-9816Disclosure(mattermost / mattermost_server)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mattermost mattermost_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import.. Mattermost Advisory ID: MMSA-2026-00685

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mattermost_server

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-17); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
mattermost_server

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-17: 3Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-17: 3Technical Details · 2026-08-18: 108-1708-18
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-173
Disclosure2General1
2026-08-181
Patch1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-9816 Mattermost versions 11.7.x &lt;= 11.7.6, 10.11.x &lt;= 10.11.21, 11.8.x &lt;= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths w… https://www.cve.org/CVERecord?id=CVE-2026-9816

    Post summary

    The statement reports a validation flaw in Mattermost’s BoardMember.Scheme* fields for specific versions but provides no evidence of exploitation, PoC, or remediation.

    000211.5K
    58.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High incorrect authorization in #Mattermost CVE-2026-9816 CVSS: 8.3 It can lead to privilege escalation. Update to v 11.7.7, 10.11.22, 11.8.4 or later. #Patch #Patch #Patch

    Post summary

    The advisory alerts users to a high‑severity incorrect authorization flaw (CVE‑2026‑9816) in Mattermost and recommends updating to the specified patch versions to mitigate the risk.

    01000299
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9816 Mattermost Board Admin Privilege Escalation via Server-Side Validation Flaw https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9816

    Post summary

    The post references CVE‑2026‑9816 as a Mattermost admin privilege‑escalation flaw linked to server‑side validation, but offers no PoC, exploit, active‑use evidence, or patch guidance.

    00000123
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9816 Mattermost versions 11.7.x &lt;= 11.7.6, 10.11.x &lt;= 10.11.21, 11.8.x &lt;= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths w… https://www.cve.org/CVERecord?id=CVE-2026-9816 ----- Traducción: CVE-2026-9816 Mat… https://infoflow.cloud`

    Post summary

    Mattermost CVE-2026-9816 is disclosed as affecting specific 10.11.x, 11.7.x, and 11.8.x versions, with the issue described as a server-side validation failure on insert and archive-import paths.

    0000079
    100 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmattermostmattermost_server---

Explore more