What is CVE-2026-16048?
In certain Mattermost versions, a channel administrator can gain additional permissions via the channel member roles API due to a failure to restrict role assignment to channel-scoped roles. This allows privilege escalation within the channel. Affected instances should be updated to the latest patched versions.
Azərbaycanca: Mattermost-un müəyyən versiyalarında kanal administratoru, kanal üzv rollarının təyin edilməsində məhdudiyyət olmaması səbəbindən 'channel member roles API' vasitəsilə əlavə icazələr əldə edə bilər. Bu zəiflikdən istifadə edərək istifadəçi öz səlahiyyətlərini artıra bilər. Təsirə məruz qalan versiyaları ən son təhlükəsizlik yeniləmələrinə qədər yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Mattermost
FAQ2
Under what conditions can CVE-2026-16048 be exploited?
In affected Mattermost versions, a channel administrator can gain additional permissions via the channel member roles API due to a failure to restrict role assignment to channel-scoped roles.
How can one protect against CVE-2026-16048?
Affected Mattermost instances should be updated to the latest patched versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.