CVE-2026-6739: Mattermost doesn't require system-level permission when patching protected default system roles
(updated )
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system roles, which allows authenticated users with delegated user-management permissions to escalate privileges by altering built-in role permissions via the role patch API. Mattermost Advisory ID: MMSA-2026-00656
References
- github.com/advisories/GHSA-m2w9-h2mm-79qr
- github.com/mattermost/mattermost/commit/2c89c2f6768fbe4dfd57a21ca38c0aecead8d4a8
- github.com/mattermost/mattermost/commit/5e159647b16e571b327ac6882f32eae42971f540
- github.com/mattermost/mattermost/commit/8000e5933526f4fd66b92131db3a1b1f4520dbae
- github.com/mattermost/mattermost/commit/f0a390b96e4c730daedbaf5190684776730218c7
- github.com/mattermost/mattermost/pull/36197
- github.com/mattermost/mattermost/pull/36377
- github.com/mattermost/mattermost/pull/36379
- github.com/mattermost/mattermost/pull/36380
- github.com/mattermost/mattermost/pull/36382
- github.com/mattermost/mattermost/releases/tag/v10.11.16
- github.com/mattermost/mattermost/releases/tag/v11.5.5
- github.com/mattermost/mattermost/releases/tag/v11.6.2
- github.com/mattermost/mattermost/releases/tag/v11.7.0
- mattermost.com/security-updates
- nvd.nist.gov/vuln/detail/CVE-2026-6739
Code Behaviors & Features
Detect and mitigate CVE-2026-6739 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →