Mattermost Boards Board-Creation Permission Not Enforced
Mattermost through 11.9.0 fails to enforce board-creation permissions, letting any authenticated user create boards regardless of their role.
- Vendor
- Mattermost
- Product
- Mattermost (Boards)
- CVSS
- 4.3
- EPSS (exploit probability)
- 0.2%
- Status
- patched
- Published
CVE-2026-14344 is a permissions enforcement failure in Mattermost Boards. The board-creation RBAC check is not applied on affected versions, so any authenticated user can create a board regardless of the role-based permissions configured by an administrator.
Affected versions: Mattermost 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22.
Fix: Upgrade to a patched release for your branch. See the Mattermost security updates page for the current patched versions.
Interim mitigation: No bypass of the RBAC control is possible once patched. If immediate patching is not feasible, restrict Mattermost server network access to minimize exposure from unanticipated users.
