Impact
Mattermost versions 10.11.x up to 10.11.19, 11.6.x up to 11.6.4, and 11.7.x up to 11.7.2 improperly allow a configured incoming webhook to post or direct messages as an arbitrary user without checking that the webhook’s owner has access to the target team or channel. An attacker who has webhook‑management permissions can therefore craft webhook settings and payloads to impersonate other users. The weakness is an authorization flaw (CWE‑639).
Affected Systems
The vulnerability affects Mattermost installations running versions 10.11.0 through 10.11.19, 11.6.0 through 11.6.4, or 11.7.0 through 11.7.2. Upgrading to 10.11.20, 11.6.5, 11.7.3, or 11.8.0 or later removes the flaw.
Risk and Exploitability
The CVSS score of 4.9 classifies the issue as moderate severity. The EPSS score of < 1 % indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog Exploitation requires the attacker to possess webhook‑management permissions within the Mattermost instance, after which they can construct a webhook configuration that masquerades messages under an arbitrary user’s identity.
OpenCVE Enrichment