Mattermost doesn't require system-level permission when patching protected default system roles
Moderate severity
GitHub Reviewed
Published
Jun 12, 2026
to the GitHub Advisory Database
•
Updated Aug 24, 2026
Package
Affected versions
= 11.6.0
>= 11.5.0, <= 11.5.4
>= 10.11.0, <= 10.11.15
Patched versions
11.6.1
11.5.5
10.11.17
>= 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260501142004-99b73d4c4acf
8.0.0-20260501142004-99b73d4c4acf
Description
Published by the National Vulnerability Database
Jun 12, 2026
Published to the GitHub Advisory Database
Jun 12, 2026
Reviewed
Aug 24, 2026
Last updated
Aug 24, 2026
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system roles, which allows authenticated users with delegated user-management permissions to escalate privileges by altering built-in role permissions via the role patch API. Mattermost Advisory ID: MMSA-2026-00656
References