Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-10527

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations via the Boards REST API or UI.. Mattermost Advisory ID: MMSA-2026-00691
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 5.0%
CVSS Severity
CVSS v3 Score 6.3
Products affected by CVE-2026-10527


Contact Us

Shodan ® - All rights reserved