SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-10106

MEDIUM · CVSS 6.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.x up to 11.7.2, 11.6.x up to 11.6.4, and 10.11.x up to 10.11.19 are vulnerable due to improper verification of action cookies, allowing authenticated users to perform actions on private channel posts without proper access. This could lead to unauthorized interactions with sensitive content, potentially compromising user privacy and data integrity. Organizations using these Mattermost versions, especially those handling confidential communications, should prioritize applying the necessary updates to mitigate this risk.

CVE
CVE-2026-10106
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690

Related CVEs

Other vulnerabilities affecting the same vendor(s)