CVE-2026-10106: Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10106?
CVE-2026-10106 has a medium severity score of 6.5.
How do I fix CVE-2026-10106?
To fix CVE-2026-10106, update Mattermost to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-10106?
Authenticated users on Mattermost versions 11.7.x, 11.6.x, and 10.11.x can be affected by CVE-2026-10106.
What type of vulnerability is CVE-2026-10106?
CVE-2026-10106 is an authorization issue that allows unauthorized users to trigger actions in private channels.
What does CVE-2026-10106 allow an attacker to do?
CVE-2026-10106 allows an authenticated user to perform interactive post actions in private channels without proper access.