CVE-2026-16048: Mattermost Server

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697

Affected products

  • Mattermost Mattermost Server: from 10.11.0, before 10.11.22 (fixed in 10.11.22); from 11.7.0, before 11.7.7 (fixed in 11.7.7); from 11.8.0, before 11.8.3 (fixed in 11.8.3)

Published 2026-08-17. Last modified 2026-08-18.