Junglewise Threat Intelligence

CVE-2026-9708: Mattermost authorization bypass in incoming webhooks

CVE-2026-9708 · Severity: medium · CVSS 4.9 · Published 2026-07-13

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost is a collaboration platform used for team communication and incident response. A security flaw in the platform's webhook system allows users with administrative permissions to send messages that appear to come from other users, even in channels they shouldn't have access to. This could be used to spread misinformation or impersonate colleagues within the organization.

Technical details

An authorization bypass (CWE-639) exists in Mattermost Server's incoming webhook implementation. The application fails to verify if the user account associated with a webhook has the necessary permissions to access the destination team or channel. An attacker with webhook management permissions (typically requiring high privileges) can craft webhook configurations and payloads to post messages or direct messages that are falsely attributed to other users. This vulnerability is addressed in versions 11.8.0, 11.7.3, 11.6.5, and 10.11.20.

Affected products

  • Mattermost Mattermost Server 11.7.0 - 11.7.2, 11.6.0 - 11.6.4, 10.11.0 - 10.11.19

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory

References

Related threats