Mattermost Channel Access Vulnerability Allowing Unauthorized Post Actions

Vulnerability

A vulnerability exists in Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19. The issue arises because the application fails to properly verify that the channel referenced in an action cookie corresponds to the channel of the target post. This flaw enables an authenticated user without access to a private channel to invoke interactive post actions on posts within that channel, using a cookie obtained from any accessible channel.

Impact

Exploitation of this vulnerability allows for unauthorized interaction with posts in private channels, potentially leading to unintended modifications or actions on those posts.

Remediation

Users can upgrade to Mattermost version 11.8.0 or later to address this vulnerability.

Added: Jul 13, 2026, 9:33 AM
Updated: Jul 13, 2026, 9:33 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.