Impact
Mattermost versions 11.9.x ≤ 11.9.0, 11.8.x ≤ 11.8.4, 11.7.x ≤ 11.7.7, and 10.11.x ≤ 10.11.22 do not validate channel action ownership, allowing an authenticated channel manager to update actions in channels they do not own. This flaw enables alteration of automated workflows and modification of content within those channels, effectively changing expected channel behavior.
Affected Systems
Mattermost Mattermost installations running any of the affected versions listed above.
Risk and Exploitability
The CVSS score of 5 indicates medium severity; exploitation likelihood remains uncertain. Exploitation requires an authenticated channel manager role and is confined to operational Mattermost deployments. It is not listed in KEV, suggesting no publicly documented exploitation. The absence of proper access control permits privilege escalation, allowing authenticated users to modify actions outside their authorized channels.
OpenCVE Enrichment