PatchSiren cyber security CVE debrief
CVE-2026-6739 Mattermost CVE debrief
CVE-2026-6739 is a medium-severity vulnerability in Mattermost that affects versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16. The vulnerability allows authenticated users with delegated user-management permissions to escalate privileges by altering built-in role permissions via the role patch API. This is due to the failure of the system to require system-level permission when patching protected default system roles.
- Vendor
- Mattermost
- Product
- Unknown
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-12
- Original CVE updated
- 2026-06-12
- Advisory published
- 2026-06-12
- Advisory updated
- 2026-06-12
Who should care
Users of Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16 who have delegated user-management permissions
Technical summary
The vulnerability has a CVSS score of 6.7 and is classified as CWE-863. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L.
Defensive priority
medium
Recommended defensive actions
- Update to a non-affected version of Mattermost
- Restrict user-management permissions to trusted users
Evidence notes
The vulnerability was reported by [email protected] and has a Mattermost Advisory ID of MMSA-2026-00656.
Official resources
-
CVE-2026-6739 CVE record
CVE.org
-
CVE-2026-6739 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
CVE-2026-6739 was published on 2026-06-12T17:16:27.290Z and has not been modified since then.