Skip to content
feed: live
>_0dayNews
CVE Record
[ MEDIUM ]CVE-2026-14344

Mattermost Boards Board-Creation Permission Not Enforced

Mattermost through 11.9.0 fails to enforce board-creation permissions, letting any authenticated user create boards regardless of their role.

cat cve-2026-14344.json
Vendor
Mattermost
Product
Mattermost (Boards)
CVSS
4.3
EPSS (exploit probability)
0.2%
Status
patched
Published

CVE-2026-14344 is a permissions enforcement failure in Mattermost Boards. The board-creation RBAC check is not applied on affected versions, so any authenticated user can create a board regardless of the role-based permissions configured by an administrator.

Affected versions: Mattermost 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22.

Fix: Upgrade to a patched release for your branch. See the Mattermost security updates page for the current patched versions.

Interim mitigation: No bypass of the RBAC control is possible once patched. If immediate patching is not feasible, restrict Mattermost server network access to minimize exposure from unanticipated users.