CVE-2026-14344: Inconsistent authorization checks in Mattermost Boards endpoints
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, and archive-import endpoints.. Mattermost Advisory ID: MMSA-2026-00715
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.11.23 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MMSA-2026-00715
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Mattermost user who lacks the board-creation permission can exploit the affected endpoints. No user interaction is required.
Which actions can bypass the board-creation permission?
The bypass affects board creation through the board duplicate, boards-and-blocks, and archive-import endpoints.
Which Mattermost releases are affected?
Affected releases are Mattermost 11.9.0 and earlier in the 11.9.x line, 11.8.4 and earlier in 11.8.x, 11.7.7 and earlier in 11.7.x, and 10.11.22 and earlier in 10.11.x.