Junglewise Threat Intelligence

CVE-2026-10103: Mattermost Server authorization bypass in shared channel sync

CVE-2026-10103 · Severity: medium · CVSS 4.3 · Published 2026-07-13

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost is a collaboration platform used for secure team communication. A vulnerability in the shared channel feature allows a connected remote organization to modify or delete messages they do not own. This could lead to unauthorized tampering with communication history or the removal of important information within shared channels.

Technical details

An authorization bypass (CWE-639) exists in the shared channel inbound sync handler of Mattermost Server. The component fails to properly verify the ownership of a post before processing synchronization requests. An attacker operating an authenticated remote cluster can send crafted sync messages referencing arbitrary post IDs within shared channels. This allows the remote cluster to modify or delete posts authored by local users or other remote clusters. The vulnerability is fixed in versions 11.7.3, 11.6.5, and 10.11.20.

Affected products

  • Mattermost Mattermost Server 11.7.0 - 11.7.2, 11.6.0 - 11.6.4, 10.11.0 - 10.11.19

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory

References

Related threats