CVE-2026-7387: Mattermost Server

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665

Affected products

  • Mattermost Mattermost Server: from 10.11.0, before 10.11.17 (fixed in 10.11.17); from 11.5.0, before 11.5.5 (fixed in 11.5.5); from 11.6.0, before 11.6.2 (fixed in 11.6.2)

Published 2026-06-12. Last modified 2026-06-18.