SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-10103

MEDIUM · CVSS 4.3 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.x up to 11.7.2, 11.6.x up to 11.6.4, and 10.11.x up to 10.11.19 are vulnerable due to inadequate verification of post ownership in the shared channel inbound sync handler. This flaw allows authenticated remote clusters to manipulate or delete posts created by local users or other remote users through specially crafted sync messages, potentially leading to data loss or integrity issues. Organizations using these Mattermost versions, especially those with shared channels, should prioritize applying the necessary updates to mitigate this risk.

CVE
CVE-2026-10103
Severity
MEDIUM
CVSS
4.3
EPSS
0.14%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that remote.. Mattermost Advisory ID: MMSA-2026-00689

Related CVEs

Other vulnerabilities affecting the same vendor(s)