CVE-2026-14259: Board archive import bypasses team board creation permissions
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00712
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.23
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated, non-guest member of a Mattermost team can exploit it. Guest users are not identified as affected by the advisory.
What does an attacker need to do to bypass the restriction?
The attacker needs to import a crafted .boardarchive file. This can create Open or Private boards even where administrators have restricted team board creation.
Which Mattermost releases are affected?
Affected releases are Mattermost 11.9.0 and earlier 11.9.x versions, 11.8.4 and earlier 11.8.x versions, 11.7.7 and earlier 11.7.x versions, and 10.11.22 and earlier 10.11.x versions.