CVE 8.8 HIGH

Mattermost group syncable endpoints allow privilege escalation via scheme_admin_CVE-2026-7387

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665

AI Analysis

Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, allowing a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.

Basic Information

ID CVE-2026-7387
Source Mattermost
Published Jun 12, 2026 at 15:54

Affected Product

Vendor Mattermost
Product Mattermost
Version 11.6.0
Affected Versions Mattermost Mattermost 11.6.0
Mattermost Mattermost 11.5.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 10.11.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Mattermost
Product Mattermost
Version 11.6.0, 11.5.0, 10.11.0, 10.11.15, 10.11.16

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.