Executive brief
Mattermost, a team communication and collaboration platform, fails to properly enforce administrator restrictions on board creation when users import archive files. An authenticated team member can bypass these restrictions by importing a specially crafted archive file, allowing them to create boards that should be prohibited by their administrator. This undermines administrative control over team workspace governance.
Technical details
This vulnerability is an authorization bypass in Mattermost's board archive import functionality. The affected versions fail to validate board creation permissions during the import process for .boardarchive files, allowing authenticated non-guest team members to create Open or Private boards regardless of administrator-configured restrictions. The attack requires the attacker to be an authenticated team member and to craft a malicious .boardarchive file. An authenticated attacker can exploit this to circumvent administrative governance controls on board creation. Patches are available in later versions of the affected release branches (11.9.1+, 11.8.5+, 11.7.8+, 10.11.23+).
Affected products
- Mattermost Mattermost Server 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22
Timeline
- 2026-09-14: disclosed