CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0305 [1.00] [M/H] Vulnerabilities patched in Mattermost

unknownCVE-2026-10080CVE-2026-10527CVE-2026-15754CVE-2026-16044CVE-2026-16045CVE-2026-16046
Mattermost, Inc. has patched vulnerabilities in Mattermost versions 10.11.x, 11.7.x and 11.8.x, including the GitLab plugin up to version 11.8. The vulnerabilities concern multiple aspects of the Mattermost software, including improper validation of WebSocket command fields, incorrect reconciliation of SchemeAdmin flags, and insufficient verification of channel ownership at ABAC policy unassign endpoints. This allows authenticated users to, among other things, cause denial-of-service by crashing plugin processes, retain administrative privileges after demotion, and make unauthorized changes to access control policies and board roles. Additionally, guest users can escalate their privileges to Board Admin via specially crafted board archive files. OAuth applications can revoke tokens and authorizations of other integrations through insufficient restrictions on account management endpoints. It is also possible to modify completed playbook runs due to missing run-state validation. Furthermore, users without sufficient read permissions can link boards to channels, exposing private channel memberships. Channel administrators can escalate their permissions via manipulation of the channel member roles API. The GitLab plugin exhibits a vulnerability allowing bots to inject messages with arbitrary URLs into channels without access rights. Thread membership records are not deleted upon leaving a team, which can grant access to private thread content upon rejoining. Finally, there is a vulnerability in server-side validation of BoardMember.Scheme* fields, allowing privilege escalation by assigning board admin rights to arbitrary users, and a permission check is missing when relinking boards to channels via the batch endpoint.

CSIRTS triage

What
Multiple vulnerabilities including improper WebSocket validation, incorrect admin flag reconciliation, and insufficient ABAC verification allow privilege escalation, denial-of-service, and unauthorized access control changes.
Who is affected
Mattermost versions 10.11.x, 11.7.x, and 11.8.x, including GitLab plugin up to 11.8, affecting authenticated users and guest users.
Urgency
Medium to High severity; authenticated users can escalate privileges and crash processes; guest users can become Board Admin.
Action
Update Mattermost to patched versions after 10.11.x, 11.7.x, and 11.8.x addressing CVE-2026-10080, CVE-2026-10527, CVE-2026-15754, CVE-2026-16044, CVE-2026-16045, CVE-2026-16046, CVE-2026-16047, and CVE-2026-16048.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Mattermost

Get an email when a new Mattermost advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-19
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0305

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-10080coverage & exploitation statusNVD · CVE.org
CVE-2026-10527coverage & exploitation statusNVD · CVE.org
CVE-2026-15754coverage & exploitation statusNVD · CVE.org
CVE-2026-16044coverage & exploitation statusNVD · CVE.org
CVE-2026-16045coverage & exploitation statusNVD · CVE.org
CVE-2026-16046coverage & exploitation statusNVD · CVE.org
CVE-2026-16047coverage & exploitation statusNVD · CVE.org
CVE-2026-16048coverage & exploitation statusNVD · CVE.org
CVE-2026-16049coverage & exploitation statusNVD · CVE.org
CVE-2026-9693coverage & exploitation statusNVD · CVE.org
CVE-2026-9816coverage & exploitation statusNVD · CVE.org
CVE-2026-9859coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Mattermost

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories