NCSC-2026-0305 [1.00] [M/H] Vulnerabilities patched in Mattermost
Mattermost, Inc. has patched vulnerabilities in Mattermost versions 10.11.x, 11.7.x and 11.8.x, including the GitLab plugin up to version 11.8. The vulnerabilities concern multiple aspects of the Mattermost software, including improper validation of WebSocket command fields, incorrect reconciliation of SchemeAdmin flags, and insufficient verification of channel ownership at ABAC policy unassign endpoints. This allows authenticated users to, among other things, cause denial-of-service by crashing plugin processes, retain administrative privileges after demotion, and make unauthorized changes to access control policies and board roles. Additionally, guest users can escalate their privileges to Board Admin via specially crafted board archive files. OAuth applications can revoke tokens and authorizations of other integrations through insufficient restrictions on account management endpoints. It is also possible to modify completed playbook runs due to missing run-state validation. Furthermore, users without sufficient read permissions can link boards to channels, exposing private channel memberships. Channel administrators can escalate their permissions via manipulation of the channel member roles API. The GitLab plugin exhibits a vulnerability allowing bots to inject messages with arbitrary URLs into channels without access rights. Thread membership records are not deleted upon leaving a team, which can grant access to private thread content upon rejoining. Finally, there is a vulnerability in server-side validation of BoardMember.Scheme* fields, allowing privilege escalation by assigning board admin rights to arbitrary users, and a permission check is missing when relinking boards to channels via the batch endpoint.
CSIRTS triage
- What
- Multiple vulnerabilities including improper WebSocket validation, incorrect admin flag reconciliation, and insufficient ABAC verification allow privilege escalation, denial-of-service, and unauthorized access control changes.
- Who is affected
- Mattermost versions 10.11.x, 11.7.x, and 11.8.x, including GitLab plugin up to 11.8, affecting authenticated users and guest users.
- Urgency
- Medium to High severity; authenticated users can escalate privileges and crash processes; guest users can become Board Admin.
- Action
- Update Mattermost to patched versions after 10.11.x, 11.7.x, and 11.8.x addressing CVE-2026-10080, CVE-2026-10527, CVE-2026-15754, CVE-2026-16044, CVE-2026-16045, CVE-2026-16046, CVE-2026-16047, and CVE-2026-16048.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Mattermost
Get an email when a new Mattermost advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0305
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-100800.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-105270.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-157540.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-160440.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-160450.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-160460.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-160470.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-160480.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-160490.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-96930.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-10080 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10527 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15754 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16044 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16045 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16046 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16047 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16048 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16049 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9693 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9816 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9859 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMattermost security advisory (AV26-828)cccs
- lowCVE-2026-9693: Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread mem…nvd
- mediumCVE-2026-9859: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce Per…nvd
- highCVE-2026-9816: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate Bo…nvd
- mediumCVE-2026-10080: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate …nvd
- mediumCVE-2026-16049: Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to ve…nvd
- mediumCVE-2026-16048: Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict c…nvd
- mediumCVE-2026-16047: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate t…nvd
- mediumCVE-2026-16046: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation…nvd
- mediumCVE-2026-16045: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth …nvd
- mediumCVE-2026-16044: Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from rec…nvd
- mediumCVE-2026-15754: Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endp…nvd
Recent advisories for Mattermost
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-71366: A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification back…nvd · 2026-08-24
- unknownMattermost security advisory (AV26-828)cccs · 2026-08-18
- medium[NEW] [medium] Mattermost Desktop: Multiple vulnerabilitiescert-bund · 2026-08-18
- medium[NEW] [medium] Mattermost: Multiple vulnerabilities allow unspecified attackcert-bund · 2026-08-18
- unknownMultiple vulnerabilities in Mattermost Desktop App (August 18, 2026)cert-fr-avis · 2026-08-18
- lowCVE-2026-9693: Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread mem…nvd · 2026-08-17
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21