Mattermost · Mattermost · CVE-2026-9859
**Name of the Vulnerable Software and Affected Versions**
Mattermost versions 11.7.0 through 11.7.6
Mattermost versions 10.11.0 through 10.11.21
Mattermost versions 11.8.0 through 11.8.3
**Description**
The Boards plugin fails to enforce the `PermissionManageBoardRoles` authorization on the `channelId` field of the batch endpoint. This allows an authenticated user with board editor privileges to relink any board they have permission to edit to an arbitrary channel by sending a crafted PATCH request.
**Recommendations**
Update Mattermost versions 11.7.0 through 11.7.6 to a version newer than 11.7.6.
Update Mattermost versions 10.11.0 through 10.11.21 to a version newer than 10.11.21.
Update Mattermost versions 11.8.0 through 11.8.3 to a version newer than 11.8.3.