CVE-2026-10527: Boards plugin retains Board Admin rights for users demoted to System Guest
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations via the Boards REST API or UI.. Mattermost Advisory ID: MMSA-2026-00691
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.7 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.22 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10527?
The severity of CVE-2026-10527 is rated as medium with a score of 6.3.
How do I fix CVE-2026-10527?
To fix CVE-2026-10527, update to Mattermost versions 11.7.7, 10.11.22, or 11.8.4 or later.
What are the consequences of CVE-2026-10527?
CVE-2026-10527 allows demoted users to retain Board Admin privileges, potentially allowing unauthorized access to admin-only operations.
Which Mattermost versions are affected by CVE-2026-10527?
Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 are affected by CVE-2026-10527.
What is the nature of the vulnerability in CVE-2026-10527?
CVE-2026-10527 is a role escalation vulnerability where users demoted to System Guest retain administrative rights in the Boards plugin.