Impact
Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19 fail to verify that a user sending a sync message actually owns the post it references (CWE-639). An authenticated remote cluster connected via a Mattermost Connected Workspace can therefore craft inbound sync messages that reference arbitrary post IDs in shared channels and modify or delete those posts even though the cluster does not own them. This flaw permits an attacker with access to a remote cluster to tamper with the integrity of posts authored by local users or other remote clusters, potentially erasing evidence or inserting falsified content. The impact is limited to the integrity of individual posts; it does not affect system availability or provide broader privileges beyond the erroneous post modifications.
Affected Systems
Affected products are Mattermost instances running the vulnerable versions listed above. Any commercial deployment using Mattermost 10.11.x (up to 10.11.19), 11.6.x (up to 11.6.4), or 11.7.x (up to 11.7.2) that participates in Connected Workspaces shared channels.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate base risk. EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation campaigns. An attacker must already have authenticated access to a remote cluster; therefore the attack vector is internal or cross‑cluster within an organization. While no public exploits have been reported, the flaw presents a tangible threat to post integrity for any organization relying on shared channels.
OpenCVE Enrichment