What is CVE-2026-16044?
CVE-2026-16044 is a vulnerability in Mattermost where guest users can gain Board Admin privileges during board archive import on versions 11.7.x through 11.7.6 and 10.11.x through 10.11.21. This allows a board member to escalate a guest user by importing a crafted .boardarchive file. Users should update Mattermost to the latest patched version and avoid importing untrusted archive files.
Azərbaycanca: CVE-2026-16044, Mattermost platformunda qonaq istifadəçilərin lövhə arxiv idxalı zamanı səhvən Board Admin səlahiyyətləri əldə etməsinə imkan verən boşluqdur. Bu zəiflik 11.7.x (≤ 11.7.6) və 10.11.x (≤ 10.11.21) versiyalarına təsir edir. İstifadəçilər Mattermost-u ən son versiyaya yeniləməli və etibarsız .boardarchive fayllarını idxaldan çəkinməlidir.
Related CVEs
link basis: same weakness class CWE-269; shared vendor: Mattermost
FAQ2
Which versions of Mattermost are affected by CVE-2026-16044?
CVE-2026-16044 affects Mattermost versions 11.7.x through 11.7.6 and 10.11.x through 10.11.21.
How can users protect against CVE-2026-16044?
Users should update Mattermost to the latest patched version and avoid importing untrusted .boardarchive files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.