Mattermost · Mattermost · CVE-2026-16047
**Name of the Vulnerable Software and Affected Versions**
Mattermost versions 11.7.0 through 11.7.6
Mattermost versions 10.11.0 through 10.11.21
Mattermost versions 11.8.0 through 11.8.3
**Description**
An authenticated attacker can discover the membership of private channels within the same team. This occurs because the system fails to validate if a user has read access to a channel before linking a board to it. The issue can be exploited by creating, patching, importing, or bulk-creating boards using an arbitrary `channelId`.
**Recommendations**
Update Mattermost versions 11.7.0 through 11.7.6 to a version newer than 11.7.6.
Update Mattermost versions 10.11.0 through 10.11.21 to a version newer than 10.11.21.
Update Mattermost versions 11.8.0 through 11.8.3 to a version newer than 11.8.3.