What is CVE-2026-16047?
A vulnerability in Mattermost where authenticated users can discover membership of private channels by linking a board without proper read access validation. This affects versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, and 11.8.x <= 11.8.3. Update Mattermost to the latest patched version to mitigate the issue.
Azərbaycanca: Mattermost-da autentifikasiya olunmuş istifadəçinin board linki vasitəsilə private channellərin üzvlərini öyrənməsinə imkan verən zəiflik. Bu, read access-in yoxlanılmaması səbəbindən baş verir. Təsirə məruz qalmamaq üçün Mattermost-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Mattermost
FAQ2
What is the vulnerability in Mattermost that allows private channel information leakage via board links?
CVE-2026-16047 allows authenticated users to discover membership of private channels by linking a board without proper read access validation.
How can I protect my Mattermost instance from this vulnerability?
Update Mattermost to the latest patched version to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.