CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15754

mediumCVSS 4.2covered by 2 sourcesfirst seen 2026-08-17
Mattermost, Inc. has patched vulnerabilities in Mattermost versions 10.11.x, 11.7.x and 11.8.x, including the GitLab plugin up to version 11.8. The vulnerabilities concern multiple aspects of the Mattermost software, including improper validation of WebSocket command fields, incorrect reconciliation of SchemeAdmin flags, and insufficient verification of channel ownership at ABAC policy unassign endpoints. This allows authenticated users to, among other things, cause denial-of-service by crashing plugin processes, retain administrative privileges after demotion, and make unauthorized changes to access control policies and board roles. Additionally, guest users can escalate their privileges to Board Admin via specially crafted board archive files. OAuth applications can revoke tokens and authorizations of other integrations through insufficient restrictions on account management endpoints. It is also possible to modify completed playbook runs due to missing run-state validation. Furthermore, users without sufficient read permissions can link boards to channels, exposing private channel memberships. Channel administrators can escalate their permissions via manipulation of the channel member roles API. The GitLab plugin exhibits a vulnerability allowing bots to inject messages with arbitrary URLs into channels without access rights. Thread membership records are not deleted upon leaving a team, which can grant access to private thread content upon rejoining. Finally, there is a vulnerability in server-side validation of BoardMember.Scheme* fields, allowing privilege escalation by assigning board admin rights to arbitrary users, and a permission check is missing when relinking boards to channels via the batch endpoint.

CSIRTS triage

What
Multiple vulnerabilities including improper WebSocket validation, incorrect admin flag reconciliation, and insufficient ABAC verification allow privilege escalation, denial-of-service, and unauthorized access control changes.
Who is affected
Mattermost versions 10.11.x, 11.7.x, and 11.8.x, including GitLab plugin up to 11.8, affecting authenticated users and guest users.
Urgency
Medium to High severity; authenticated users can escalate privileges and crash processes; guest users can become Board Admin.
Action
Update Mattermost to patched versions after 10.11.x, 11.7.x, and 11.8.x addressing CVE-2026-10080, CVE-2026-10527, CVE-2026-15754, CVE-2026-16044, CVE-2026-16045, CVE-2026-16046, CVE-2026-16047, and CVE-2026-16048.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-15754

Get an email if CVE-2026-15754 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-15754

CVE.org record

Embed the live status

CVE-2026-15754 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15754 status](https://www.csirts.com/badge/CVE-2026-15754)](https://www.csirts.com/cve/CVE-2026-15754)