A vulnerability described as critical has been identified in Mattermost up to 10.11.21/11.7.6/11.8.3. The impacted element is an unknown function of the component Board Member Validation. Such manipulation of the argument BoardMember.Scheme leads to improper privilege management.
This vulnerability is listed as CVE-2026-9816. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.