Access Control Flaw in Mattermost Affects Board Linking Functionality
CVE-2026-16047

4.3MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
17 August 2026

What is CVE-2026-16047?

In specific versions of Mattermost, an access control vulnerability allows authenticated users to link boards to channels without proper validation of read access. This flaw may allow attackers to indirectly ascertain the membership of private channels within the same team by creating or modifying boards with arbitrary channel identifiers. This could lead to unintended exposure of sensitive information within private communications.

Affected Version(s)

Mattermost 11.7.0 <= 11.7.6

Mattermost 10.11.0 <= 10.11.21

Mattermost 11.8.0 <= 11.8.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GuyNesher
.