Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-16044

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00672
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 6.7%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-16044


Contact Us

Shodan ® - All rights reserved