CyberRota Analysis
AI-GeneratedMattermost versions 11.7.x up to 11.7.2, 11.6.x up to 11.6.4, and 10.11.x up to 10.11.19 are vulnerable due to improper verification of action cookies, allowing authenticated users to perform actions on private channel posts without proper access. This could lead to unauthorized interactions with sensitive content, potentially compromising user privacy and data integrity. Organizations using these Mattermost versions, especially those handling confidential communications, should prioritize applying the necessary updates to mitigate this risk.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690
Related CVEs
Other vulnerabilities affecting the same vendor(s)