Access Control Flaw in Mattermost Affects Board Linking Functionality
CVE-2026-16047
4.3MEDIUM
What is CVE-2026-16047?
In specific versions of Mattermost, an access control vulnerability allows authenticated users to link boards to channels without proper validation of read access. This flaw may allow attackers to indirectly ascertain the membership of private channels within the same team by creating or modifying boards with arbitrary channel identifiers. This could lead to unintended exposure of sensitive information within private communications.
Affected Version(s)
Mattermost 11.7.0 <= 11.7.6
Mattermost 10.11.0 <= 10.11.21
Mattermost 11.8.0 <= 11.8.3