CVE-2026-7387High· 8.8▾ TwilightMattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests. Mattermost Advisory ID: MMSA-2026-00665
github.com/mattermost/mattermost-server >= 11.6.0, < 11.6.1github.com/mattermost/mattermost-server >= 11.5.0, < 11.5.5github.com/mattermost/mattermost-server >= 10.11.0, < 10.11.17github.com/mattermost/mattermost/server/v8 >= 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260506065351-202d125afa87Upgrade to a patched release:
github.com/mattermost/mattermost-server 11.6.1github.com/mattermost/mattermost-server 11.5.5github.com/mattermost/mattermost-server 10.11.17github.com/mattermost/mattermost/server/v8 8.0.0-20260506065351-202d125afa87Connected by shared product, vendor, weakness, or advisory.
CVE-2026-3433Medium· 4.3Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
CVE-2026-6739Medium· 6.7Mattermost doesn't require system-level permission when patching protected default system roles
CVE-2026-6689Medium· 4.3Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
CVE-2026-7184Medium· 6.5Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
CVE-2026-6961High· 7.6Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
CVE-2026-6046Medium· 5.3Mattermost doesn't validate that a username returned during bot registration belongs to a bot account