Executive brief
Mattermost is a self-hosted team collaboration platform similar to Slack. A flaw in multiple versions allows channel managers to modify channel actions (automations/workflows) outside their own channels by bypassing ownership validation. This enables unauthorized modification of channel automations across the platform, potentially disrupting operations or altering automation logic in channels managed by other teams.
Technical details
The vulnerability is an authorization bypass in the channel action update endpoint. Mattermost fails to properly validate that a channel manager attempting to update a channel action actually owns the target channel, allowing cross-channel action modification. The vulnerability affects versions 10.11.x through 10.11.22, 11.7.x through 11.7.7, 11.8.x through 11.8.4, and 11.9.x through 11.9.0. An authenticated channel manager can exploit this by directly calling the channel action update endpoint with a channel action ID from a different channel. Patches are available in newer versions; users should upgrade to patched releases per Mattermost's mandatory upgrade policy.
Affected products
- Mattermost Mattermost Server 10.11.x <= 10.11.22, 11.7.x <= 11.7.7, 11.8.x <= 11.8.4, 11.9.x <= 11.9.0
Timeline
- 2026-09-14: disclosed