Channel Action Ownership Vulnerability in Mattermost
CVE-2026-10542

5MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
14 September 2026

What is CVE-2026-10542?

A vulnerability in Mattermost has been identified, where certain versions fail to properly validate ownership of channel actions. This oversight permits channel managers to alter actions in other channels through the channel action update endpoint, potentially leading to unauthorized modifications and disruption of channel integrity. Users operating on affected versions should prioritize immediate updates to ensure protection against such vulnerabilities.

Affected Version(s)

Mattermost 11.9.0

Mattermost 11.8.0 <= 11.8.4

Mattermost 11.7.0 <= 11.7.7

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

minghseinyuc86595
.