CVE-2026-9859: Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose boards to arbitrary channels
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MMSA-2026-00686 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.7.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.8.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.11.22 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9859?
CVE-2026-9859 has a medium severity rating of 6.5.
How do I fix CVE-2026-9859?
To fix CVE-2026-9859, update your Mattermost Boards plugin to a version that is not affected, specifically to versions beyond 11.7.6, 10.11.21, or 11.8.3.
What does CVE-2026-9859 affect?
CVE-2026-9859 affects Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3.
Who can exploit CVE-2026-9859?
CVE-2026-9859 can be exploited by an authenticated board editor who can craft a PATCH request to relink boards to arbitrary channels.
What is the impact of CVE-2026-9859?
The impact of CVE-2026-9859 is that it allows board editors to expose sensitive board information to unauthorized channels.