Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19 do not verify that the channel referenced in an action cookie matches the channel of the target post. This flaw, identified as CWE-863, allows an authenticated user who does not have access to a private channel to trigger interactive post actions on posts inside that private channel by using a cookie obtained from any accessible channel. The result is that the user can execute actions—such as modifying or deleting posts—without proper authorization, effectively escalating privileges for the attacker’s account.

Affected Systems

Mattermost Mattermost is affected. The vulnerable releases are 11.7.0 to 11.7.2, 11.6.0 to 11.6.4, 10.11.0 to 10.11.19. All earlier versions are not impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is < 1%, and the vulnerability is not reported in CISA's KEV catalog. Exploitation requires the attacker to be authenticated to a Mattermost instance and to possess a valid action cookie from any channel the attacker can access. The attacker then crafts a request that targets a private channel post, causing the server to process the action cookie as if it belonged to that channel. This attack is feasible over the network and could be used by insiders or compromised accounts to perform unauthorized actions within private channels.

Generated by OpenCVE AI on August 1, 2026 at 10:47 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.8.0, 11.7.3, 11.6.5, 10.11.20 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to version 11.8.0, 11.7.3, 11.6.5, or 10.11.20 or later as advised by the vendor.
  • Limit user users without access to private channels cannot trigger actions on those channels.
  • Enable auditing and monitor application logs for unusual post action activity, especially from users with access only to public channels.
  • If an upgrade cannot be performed immediately, enforce network segmentation and restrict Mattermost server access to trusted administrators until the patch is applied.

Generated by OpenCVE AI on August 1, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 13 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690
Title Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-13T13:56:41.047Z

Reserved: 2026-05-29T16:06:43.719Z

Link: CVE-2026-10106

cve-icon Vulnrichment

Updated: 2026-07-13T13:56:37.806Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:00:04Z

Weaknesses