CVE-2026-16048: Channel member roles accept out-of-scope roles
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.7 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16048?
CVE-2026-16048 is classified with a medium severity score of 6.3.
How do I fix CVE-2026-16048?
To address CVE-2026-16048, update Mattermost to versions 11.8.3, 11.7.7, or 10.11.22 or later.
What systems are affected by CVE-2026-16048?
CVE-2026-16048 affects Mattermost versions 11.8.x up to 11.8.2, 11.7.x up to 11.7.6, and 10.11.x up to 10.11.21.
What are the risks associated with CVE-2026-16048?
CVE-2026-16048 allows a channel administrator to gain unauthorized channel permissions, which can compromise channel security.
When was CVE-2026-16048 published?
CVE-2026-16048 was published on August 17, 2026.