CVE-2026-9816: Insufficient server-side validation of board member role fields permits privilege escalation
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import.. Mattermost Advisory ID: MMSA-2026-00685
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.7 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.22 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MMSA-2026-00685
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9816?
CVE-2026-9816 has a severity rating of 8.3, indicating a high level of risk.
How do I fix CVE-2026-9816?
To mitigate CVE-2026-9816, ensure that you update Mattermost to the latest version that addresses this vulnerability.
What is the impact of CVE-2026-9816?
CVE-2026-9816 allows privilege escalation by permitting unauthorized users to grant board admin rights.
Which versions of Mattermost are affected by CVE-2026-9816?
Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 are all affected by CVE-2026-9816.
Who is at risk due to CVE-2026-9816?
Board editors or non-guest team members in the affected Mattermost versions are at risk of exploiting this vulnerability.