Junglewise Threat Intelligence

CVE-2026-10106: Mattermost incorrect authorization in interactive post actions

CVE-2026-10106 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost, a collaboration and messaging platform, contains a security flaw that could allow users to interact with posts in private channels they do not have permission to access. By using a valid security token from a channel they can access, an attacker can bypass restrictions to trigger automated actions on posts in restricted areas. This could lead to unauthorized data modification or the execution of automated workflows within private team environments.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Mattermost Server where the application fails to validate the relationship between an action cookie and the target post's channel. An authenticated attacker can obtain a valid action cookie from a channel they have permission to access and reuse it to trigger interactive post actions (such as button clicks or integration triggers) on posts located in private channels they cannot normally access. The vulnerability is reachable over the network with low privileges and requires no user interaction. Patches have been released in versions 11.8.0, 11.7.3, 11.6.5, and 10.11.20.

Affected products

  • Mattermost Mattermost Server 11.7.0 - 11.7.2, 11.6.0 - 11.6.4, 10.11.0 - 10.11.19

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory

References

Related threats