Mattermost Server 10.11.x < 10.11.22 / 11.7.x < 11.7.7 Multiple Vulnerabilities (MMSA-2026-00672, MMSA-2026-00675, MMSA-2026-00704)

medium Nessus Plugin ID 338331

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Mattermost Server installed on the remote host is affected by multiple vulnerabilities as referenced in the MMSA-2026-00672, MMSA-2026-00675, MMSA-2026-00704 advisories.

- Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .boardarchive file. Mattermost Advisory ID:
MMSA-2026-00672. (CVE-2026-16044)

- Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the user's authorizations or tokens for other integrations via account-management endpoints. Mattermost Advisory ID: MMSA-2026-00704.
(CVE-2026-16045)

- Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Mattermost Advisory ID: MMSA-2026-00675. (CVE-2026-16046)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Mattermost Server version 10.11.22, 11.7.7, 11.9.0 or later.

See Also

https://mattermost.com/security-updates/

Plugin Details

Severity: Medium

ID: 338331

File Name: mattermost_server_MMSA-2026-00672_00675_00704.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/20/2026

Updated: 8/20/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.91

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

CVSS Score Source: CVE-2026-16044

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Vulnerability Information

CPE: cpe:/a:mattermost:mattermost_server

Required KB Items: installed_sw/Mattermost Server

Patch Publication Date: 7/17/2026

Vulnerability Publication Date: 8/17/2026

Reference Information

CVE: CVE-2026-16044, CVE-2026-16045, CVE-2026-16046