CyberRota Analysis
AI-GeneratedMattermost versions 11.7.x up to 11.7.2, 11.6.x up to 11.6.4, and 10.11.x up to 10.11.19 are vulnerable due to inadequate verification of post ownership in the shared channel inbound sync handler. This flaw allows authenticated remote clusters to manipulate or delete posts created by local users or other remote users through specially crafted sync messages, potentially leading to data loss or integrity issues. Organizations using these Mattermost versions, especially those with shared channels, should prioritize applying the necessary updates to mitigate this risk.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that remote.. Mattermost Advisory ID: MMSA-2026-00689
Related CVEs
Other vulnerabilities affecting the same vendor(s)