Channel Action Ownership Vulnerability in Mattermost
CVE-2026-10542
5MEDIUM
What is CVE-2026-10542?
A vulnerability in Mattermost has been identified, where certain versions fail to properly validate ownership of channel actions. This oversight permits channel managers to alter actions in other channels through the channel action update endpoint, potentially leading to unauthorized modifications and disruption of channel integrity. Users operating on affected versions should prioritize immediate updates to ensure protection against such vulnerabilities.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7