Mattermost Server 10.11.x < 10.11.22 / 11.7.x < 11.7.7 / 11.8.x < 11.8.4 Multiple Vulnerabilities (MMSA-2026-00685, MMSA-2026-00686, MMSA-2026-00687, MMSA-2026-00691)

high Nessus Plugin ID 338329

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Mattermost Server installed on the remote host is affected by multiple vulnerabilities as referenced in the MMSA-2026-00685, MMSA-2026-00686, MMSA-2026-00687, MMSA-2026-00691 advisories.

- Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import. Mattermost Advisory ID: MMSA-2026-00685. (CVE-2026-9816)

- Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686. (CVE-2026-9859)

- Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards users via a custom_focalboard_SUBSCRIBE_TEAM message with a non-string teamId.
Mattermost Advisory ID: MMSA-2026-00687. (CVE-2026-10080)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Mattermost Server version 10.11.22, 11.7.7, 11.8.4, 11.9.0 or later.

See Also

https://mattermost.com/security-updates/

Plugin Details

Severity: High

ID: 338329

File Name: mattermost_server_MMSA-2026-00685_00686_00687_00691.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/20/2026

Updated: 8/20/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.5

Percentile: 57.58

CVSS v2

Risk Factor: High

Base Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:C/A:C

CVSS Score Source: CVE-2026-9816

CVSS v3

Risk Factor: High

Base Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

Vulnerability Information

CPE: cpe:/a:mattermost:mattermost_server

Required KB Items: installed_sw/Mattermost Server

Patch Publication Date: 7/17/2026

Vulnerability Publication Date: 8/17/2026

Reference Information

CVE: CVE-2026-10080, CVE-2026-10527, CVE-2026-9816, CVE-2026-9859