CVE-2026-7387: Mattermost group syncable endpoints allow privilege escalation via scheme_admin
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the schemeadmin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.16 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.17 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Patch MMSA-2026-00665
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7387?
CVE-2026-7387 has a high severity rating of 8.8.
How do I fix CVE-2026-7387?
To fix CVE-2026-7387, update Mattermost to versions 11.7.0, 11.6.2, 11.5.5, 10.11.16, 10.11.17 or higher.
What are the affected versions for CVE-2026-7387?
The affected Mattermost versions include 11.6.x up to 11.6.1, 11.5.x up to 11.5.4, and 10.11.x up to 10.11.15.
What type of vulnerability is CVE-2026-7387?
CVE-2026-7387 is a privilege escalation vulnerability due to insufficient authorization checks.
Who is impacted by CVE-2026-7387?
Users with group-link permissions in the affected versions of Mattermost may be impacted by CVE-2026-7387.