Authorization Flaw in Mattermost Affects Board Creation
CVE-2026-14344
4.3MEDIUM
What is CVE-2026-14344?
An authorization flaw in Mattermost allows unauthorized authenticated users to create boards using various endpoints such as board duplicate, boards-and-blocks, and archive-import. This vulnerability undermines the intended permissions associated with board creation, posing potential risks to data integrity and user management within Mattermost environments.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7