Junglewise Threat Intelligence

CVE-2026-7387: Mattermost privilege escalation in group syncable link and patch endpoints

CVE-2026-7387 · Severity: high · CVSS 8.8 · Published 2026-06-12

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), Mattermost Server, github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go, Mattermost.

Executive brief

Mattermost, a popular open-source team collaboration platform, fails to properly enforce role-management authorization checks on API endpoints that manage group permissions for teams and channels. An attacker with basic group-link permissions can craft API requests to escalate themselves and other group members to team or channel administrator status without proper authorization, gaining control over team/channel settings and member access.

Technical details

This is an authorization bypass vulnerability (CWE-863) in Mattermost's group synchronization API endpoints. The group syncable link and patch endpoints fail to validate whether the caller holds role-management permissions before allowing the scheme_admin flag to be set on group members. An authenticated user with group-link permissions can send crafted API requests to escalate privileges for themselves and group members to team or channel administrator level, bypassing the intended authorization model. The vulnerability requires low privileges (group-link access) and no user interaction. Patches were released in versions 10.11.17, 11.5.5, 11.6.2, and 11.7.0, adding explicit permission checks requiring the caller to hold the role-management permission for the target team/channel or the sysconsole groups-management permission.

Affected products

  • Mattermost Mattermost Server 11.6.0 to 11.6.1, 11.5.0 to 11.5.4, 10.11.0 to 10.11.15, 10.11.0 to 10.11.16

Timeline

  • 2026-06-12: disclosed: Vulnerability published in GitHub Advisory Database
  • 2026-05-05: patched: Fixes merged into release branches (v10.11.17, v11.5.5, v11.6.2, v11.7.0)

References

Related threats