8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665
AI Analysis
Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, allowing a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.
Basic Information
ID
CVE-2026-7387
Source
Mattermost
Published
Jun 12, 2026 at 15:54
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
11.6.0
Affected Versions
Mattermost Mattermost 11.6.0
Mattermost Mattermost 11.5.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 11.5.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 10.11.0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Mattermost
Product
Mattermost
Version
11.6.0, 11.5.0, 10.11.0, 10.11.15, 10.11.16