Junglewise Threat Intelligence

CVE-2026-9816: Mattermost privilege escalation via BoardMember.Scheme validation bypass

CVE-2026-9816 · Severity: high · CVSS 8.3 · Published 2026-08-17

Technologies: Mattermost. Vendors: Mattermost.

Executive brief

Mattermost, a widely-deployed team collaboration platform, fails to properly validate board administrator permissions when importing teams or adding board members. An attacker with basic team member or board editor access can exploit this flaw to grant themselves admin rights on any board, potentially exposing sensitive team data or disrupting board operations. This affects multiple recent versions of the platform and is easily exploitable without special privileges.

Technical details

The vulnerability exists in Mattermost's BoardMember.Scheme* field validation logic, which is missing server-side checks during member insertion and archive import operations. The flaw affects the POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import endpoints. A board editor or non-guest team member can craft requests to set BoardMember.Scheme* fields to admin values, bypassing role validation and granting board admin privileges to arbitrary users including themselves. The vulnerability requires network access to the Mattermost instance and an authenticated user account with basic team or board access, but no further privilege escalation is needed.

Affected products

  • Mattermost Mattermost 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3

Timeline

  • 2026-08-17: disclosed: CVE-2026-9816 publicly disclosed; Mattermost Advisory ID MMSA-2026-00685

References

Related threats