Medium severity6.7NVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026
CVE-2026-6739
CVE-2026-6739
Description
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system roles, which allows authenticated users with delegated user-management permissions to escalate privileges by altering built-in role permissions via the role patch API.. Mattermost Advisory ID: MMSA-2026-00656
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost-serverGo | >= 11.6.0, < 11.6.1 | 11.6.1 |
github.com/mattermost/mattermost-serverGo | >= 11.5.0, < 11.5.5 | 11.5.5 |
github.com/mattermost/mattermost-serverGo | >= 10.11.0, < 10.11.17 | 10.11.17 |
github.com/mattermost/mattermost/server/v8Go | >= 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260501142004-99b73d4c4acf | 8.0.0-20260501142004-99b73d4c4acf |
Affected products
3- osv-coordsRange: < 0.0.20260827T195228-160000.1.1
<= 11.6.1, <= 11.5.4, <= 10.11.16+ 1 more
- (no CPE)range: <= 11.6.1, <= 11.5.4, <= 10.11.16
- (no CPE)range: >=10.11.0,<=10.11.16 && >=11.5.0,<=11.5.4 && >=11.6.0,<=11.6.1
Patches
Vulnerability mechanics
References
16- github.com/advisories/GHSA-m2w9-h2mm-79qrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-6739ghsaADVISORY
- github.com/mattermost/mattermost/commit/2c89c2f6768fbe4dfd57a21ca38c0aecead8d4a8ghsaWEB
- github.com/mattermost/mattermost/commit/5e159647b16e571b327ac6882f32eae42971f540ghsaWEB
- github.com/mattermost/mattermost/commit/8000e5933526f4fd66b92131db3a1b1f4520dbaeghsaWEB
- github.com/mattermost/mattermost/commit/f0a390b96e4c730daedbaf5190684776730218c7ghsaWEB
- github.com/mattermost/mattermost/pull/36197ghsaWEB
- github.com/mattermost/mattermost/pull/36377ghsaWEB
- github.com/mattermost/mattermost/pull/36379ghsaWEB
- github.com/mattermost/mattermost/pull/36380ghsaWEB
- github.com/mattermost/mattermost/pull/36382ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v10.11.16ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.5.5ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.6.2ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.7.0ghsaWEB
- mattermost.com/security-updatesnvdWEB
News mentions
1- Mattermost Discloses 7 CVEs: Privilege Escalation, Token Theft, and Federated File WriteVypr Intelligence · Jun 12, 2026