CVE-2026-9816
published 2026-08-17CVE-2026-9816: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and…
PriorityP351high8.3CVSS 3.1
AVNACLPRLUINSUCLIHAH
EPSS
0.26%
17.6th percentile
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import.. Mattermost Advisory ID: MMSA-2026-00685
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | 10.11.0 – 10.11.21 | — |
| mattermost | mattermost | 11.7.0 – 11.7.6 | — |
| mattermost | mattermost | 11.8.0 – 11.8.3 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.22 | 10.11.22 |
| mattermost | mattermost_server | >= 11.7.0 < 11.7.7 | 11.7.7 |
| mattermost | mattermost_server | >= 11.8.0 < 11.8.4 | 11.8.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mattermost up to 10.11.21/11.7.6/11.8.3 Board Member Validation BoardMember.Scheme privileges management (EUVD-2026-60540)
vuldb·2026-08-18·CVSS 8.3
CVE-2026-9816 [HIGH] Mattermost up to 10.11.21/11.7.6/11.8.3 Board Member Validation BoardMember.Scheme privileges management (EUVD-2026-60540)
A vulnerability described as critical has been identified in Mattermost up to 10.11.21/11.7.6/11.8.3. The impacted element is an unknown function of the component Board Member Validation. Such manipulation of the argument BoardMember.Scheme leads to improper privilege management.
This vulnerability is listed as CVE-2026-9816. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or no
ghsa_unreviewed·2026-08-18
CVE-2026-9816 [HIGH] CWE-863 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or no
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import.. Mattermost Advisory ID: MMSA-2026-00685
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-17
Published