PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6739 Mattermost CVE debrief

CVE-2026-6739 is a medium-severity vulnerability in Mattermost that affects versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16. The vulnerability allows authenticated users with delegated user-management permissions to escalate privileges by altering built-in role permissions via the role patch API. This is due to the failure of the system to require system-level permission when patching protected default system roles.

Vendor
Mattermost
Product
Unknown
CVSS
MEDIUM 6.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-12
Original CVE updated
2026-06-12
Advisory published
2026-06-12
Advisory updated
2026-06-12

Who should care

Users of Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16 who have delegated user-management permissions

Technical summary

The vulnerability has a CVSS score of 6.7 and is classified as CWE-863. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L.

Defensive priority

medium

Recommended defensive actions

  • Update to a non-affected version of Mattermost
  • Restrict user-management permissions to trusted users

Evidence notes

The vulnerability was reported by [email protected] and has a Mattermost Advisory ID of MMSA-2026-00656.

Official resources

CVE-2026-6739 was published on 2026-06-12T17:16:27.290Z and has not been modified since then.