SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-9708

MEDIUM · CVSS 4.9 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.2 and earlier in the 11.7.x series, 11.6.4 and earlier in the 11.6.x series, and 10.11.19 and earlier in the 10.11.x series are vulnerable due to improper validation of incoming webhook user permissions, allowing unauthorized users to post messages as other users. This vulnerability can lead to impersonation and potential data leakage within teams or channels. Organizations using affected Mattermost versions, especially those with webhook management capabilities, should prioritize remediation to mitigate risks associated with unauthorized message posting.

CVE
CVE-2026-9708
Severity
MEDIUM
CVSS
4.9
EPSS
0.21%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

Related CVEs

Other vulnerabilities affecting the same vendor(s)