Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-9859

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 17.0%
CVSS Severity
CVSS v3 Score 6.5


Contact Us

Shodan ® - All rights reserved