Security Advisory

CVE-2026-10106

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-13 08:09:58
Last updated 2026-07-13 13:56:41
Assigner Mattermost
CVSS score 6.5
State PUBLISHED

Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690