Mattermost Incoming Webhook User Access Vulnerability Allowing Impersonation

Vulnerability

A vulnerability exists in Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19. The issue arises because the application fails to properly validate whether a user assigned to an incoming webhook has the appropriate access to the designated team or channel. This flaw enables a requester with webhook management permissions to send posts or direct messages on behalf of another user by manipulating the incoming webhook configuration and payloads.

Impact

Exploitation of this vulnerability allows for unauthorized impersonation of users in posts or direct messages, potentially leading to misinformation or misuse of user identities within the Mattermost platform.

Remediation

Users can upgrade to Mattermost versions 11.8.0, 11.7.4, or 11.6.5 to address this vulnerability.

Added: Jul 13, 2026, 9:41 AM
Updated: Jul 13, 2026, 9:41 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
4.8
remediation
7.7
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.