High severity8.8NVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026
CVE-2026-7387
CVE-2026-7387
Description
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost-serverGo | >= 11.6.0, < 11.6.1 | 11.6.1 |
github.com/mattermost/mattermost-serverGo | >= 11.5.0, < 11.5.5 | 11.5.5 |
github.com/mattermost/mattermost-serverGo | >= 10.11.0, < 10.11.17 | 10.11.17 |
github.com/mattermost/mattermost/server/v8Go | >= 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260506065351-202d125afa87 | 8.0.0-20260506065351-202d125afa87 |
Affected products
2- Range: >=11.6.0, <=11.6.1 || >=11.5.0, <=11.5.4 || >=10.11.0, <=10.11.16
- osv-coordsRange: < 0.0.20260827T195228-160000.1.1
Patches
Vulnerability mechanics
References
17- github.com/advisories/GHSA-6hxm-w4hv-vgvwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-7387ghsaADVISORY
- github.com/mattermost/mattermost/commit/1ce2484a00c9821ee19708d2c46720e4855033a9ghsaWEB
- github.com/mattermost/mattermost/commit/202d125afa87fe39611686850fd82590c99ca344ghsaWEB
- github.com/mattermost/mattermost/commit/8c72083414e675c97987374395e36d1f36b4bd8aghsaWEB
- github.com/mattermost/mattermost/commit/a9e574a82633915f22071f0d7ca2b006f249ec2aghsaWEB
- github.com/mattermost/mattermost/commit/d5f29c8ebbeb04460d16d9e2635ce50deeb78428ghsaWEB
- github.com/mattermost/mattermost/pull/36316ghsaWEB
- github.com/mattermost/mattermost/pull/36423ghsaWEB
- github.com/mattermost/mattermost/pull/36431ghsaWEB
- github.com/mattermost/mattermost/pull/36432ghsaWEB
- github.com/mattermost/mattermost/pull/36434ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v10.11.16ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.5.5ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.6.2ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.7.0ghsaWEB
- mattermost.com/security-updatesnvdWEB
News mentions
1- Mattermost Discloses 7 CVEs: Privilege Escalation, Token Theft, and Federated File WriteVypr Intelligence · Jun 12, 2026