Mattermost Post Ownership Verification Vulnerability in Shared Channels

Vulnerability

A vulnerability exists in Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19. The issue arises in the shared channel inbound sync handler, where the application fails to properly verify post ownership. This flaw enables an authenticated remote cluster to alter or delete posts made by local users or other remote users. The exploitation is carried out by sending crafted sync messages that reference arbitrary post IDs in channels shared with the remote cluster.

Impact

Exploitation of this vulnerability allows for unauthorized modification or deletion of posts in shared channels, potentially disrupting communication and collaboration.

Remediation

Users can upgrade to Mattermost versions 11.8.0, 11.7.4, or 11.6.5 to address this vulnerability.

Added: Jul 13, 2026, 9:33 AM
Updated: Jul 13, 2026, 9:33 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
4.8
remediation
7.7
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.