CVE-2026-16047
Mattermost, Inc. has patched vulnerabilities in Mattermost versions 10.11.x, 11.7.x and 11.8.x, including the GitLab plugin up to version 11.8. The vulnerabilities concern multiple aspects of the Mattermost software, including improper validation of WebSocket command fields, incorrect reconciliation of SchemeAdmin flags, and insufficient verification of channel ownership at ABAC policy unassign endpoints. This allows authenticated users to, among other things, cause denial-of-service by crashing plugin processes, retain administrative privileges after demotion, and make unauthorized changes to access control policies and board roles. Additionally, guest users can escalate their privileges to Board Admin via specially crafted board archive files. OAuth applications can revoke tokens and authorizations of other integrations through insufficient restrictions on account management endpoints. It is also possible to modify completed playbook runs due to missing run-state validation. Furthermore, users without sufficient read permissions can link boards to channels, exposing private channel memberships. Channel administrators can escalate their permissions via manipulation of the channel member roles API. The GitLab plugin exhibits a vulnerability allowing bots to inject messages with arbitrary URLs into channels without access rights. Thread membership records are not deleted upon leaving a team, which can grant access to private thread content upon rejoining. Finally, there is a vulnerability in server-side validation of BoardMember.Scheme* fields, allowing privilege escalation by assigning board admin rights to arbitrary users, and a permission check is missing when relinking boards to channels via the batch endpoint.
CSIRTS triage
- What
- Multiple vulnerabilities including improper WebSocket validation, incorrect admin flag reconciliation, and insufficient ABAC verification allow privilege escalation, denial-of-service, and unauthorized access control changes.
- Who is affected
- Mattermost versions 10.11.x, 11.7.x, and 11.8.x, including GitLab plugin up to 11.8, affecting authenticated users and guest users.
- Urgency
- Medium to High severity; authenticated users can escalate privileges and crash processes; guest users can become Board Admin.
- Action
- Update Mattermost to patched versions after 10.11.x, 11.7.x, and 11.8.x addressing CVE-2026-10080, CVE-2026-10527, CVE-2026-15754, CVE-2026-16044, CVE-2026-16045, CVE-2026-16046, CVE-2026-16047, and CVE-2026-16048.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-16047
Get an email if CVE-2026-16047 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownNCSC-2026-0305 [1.00] [M/H] Vulnerabilities patched in Mattermostncsc-nl · 2026-08-19
- mediumCVE-2026-16047: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate t…nvd · 2026-08-17
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-16047)