Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpoint.. Mattermost Advisory ID: MMSA-2026-00692
Published: 2026-09-14
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of channel actions (privilege escalation).
Action: Immediate Patch
AI Analysis

Impact

Mattermost versions 11.9.x ≤ 11.9.0, 11.8.x ≤ 11.8.4, 11.7.x ≤ 11.7.7, and 10.11.x ≤ 10.11.22 do not validate channel action ownership, allowing an authenticated channel manager to update actions in channels they do not own. This flaw enables alteration of automated workflows and modification of content within those channels, effectively changing expected channel behavior.

Affected Systems

Mattermost Mattermost installations running any of the affected versions listed above.

Risk and Exploitability

The CVSS score of 5 indicates medium severity; exploitation likelihood remains uncertain. Exploitation requires an authenticated channel manager role and is confined to operational Mattermost deployments. It is not listed in KEV, suggesting no publicly documented exploitation. The absence of proper access control permits privilege escalation, allowing authenticated users to modify actions outside their authorized channels.

Generated by OpenCVE AI on September 15, 2026 at 14:31 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to version 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.
  • If upgrading cannot occur immediately, restrict channel manager permissions or disable the channel action update endpoint through Mattermost configuration.
  • Limit channel manager assignments to the minimum necessary users and audit these permissions regularly.

Generated by OpenCVE AI on September 15, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpoint.. Mattermost Advisory ID: MMSA-2026-00692
Title Playbooks channel action update validation issue
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T11:19:45.549Z

Reserved: 2026-06-01T12:34:54.592Z

Link: CVE-2026-10542

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:39.347Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:02.447

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-10542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:45:11Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key