CVE-2026-10103
Analyzed Analyzed - Analysis Complete

Mattermost Post Ownership Bypass in Shared Channels

Vulnerability report for CVE-2026-10103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-14

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that remote.. Mattermost Advisory ID: MMSA-2026-00689

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-14
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mattermost mattermost_server From 10.11.0 (inc) to 10.11.20 (exc)
mattermost mattermost_server From 11.6.0 (inc) to 11.6.5 (exc)
mattermost mattermost_server From 11.7.0 (inc) to 11.7.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects certain versions of Mattermost (11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19) where the system fails to verify post ownership in the shared channel inbound sync handler.

Because of this failure, an authenticated remote cluster can modify or delete posts authored by local users or other remote clusters by sending crafted sync messages that reference arbitrary post IDs in channels shared with that remote cluster.

Detection Guidance

Detecting this vulnerability requires verifying the installed version of Mattermost on your system. The vulnerability affects specific versions: 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, and 10.11.x <= 10.11.19.

  • Check the Mattermost server version using the Mattermost CLI or API. For example, run the following command on the server where Mattermost is installed: 'mattermost version'.
  • Alternatively, you can check the version via the Mattermost web interface by navigating to 'System Console' > 'About' > 'Server Version'.
  • Review logs for unusual activity related to shared channel sync messages, particularly those referencing post IDs that do not belong to the authenticated user or remote cluster.

If your Mattermost version falls within the affected ranges, assume the vulnerability is present and proceed with mitigation steps.

Impact Analysis

The vulnerability allows an authenticated remote cluster to alter or remove posts created by local users or other remote clusters in shared channels.

This can lead to unauthorized modification or deletion of content, potentially disrupting communication and collaboration within the affected Mattermost channels.

Compliance Impact

This vulnerability in Mattermost could impact compliance with standards and regulations like GDPR and HIPAA due to its potential to allow unauthorized modification or deletion of posts. Under GDPR, unauthorized access or alteration of personal data can lead to violations of data integrity and confidentiality requirements, potentially resulting in non-compliance penalties.

For HIPAA, if the affected Mattermost instance is used to handle protected health information (PHI), the unauthorized modification or deletion of posts could violate the HIPAA Security Rule, which mandates safeguards for electronic PHI (ePHI) to ensure its integrity and confidentiality. Failure to protect ePHI from unauthorized changes could result in compliance violations.

  • GDPR: Non-compliance risk due to unauthorized data modification or deletion, violating data integrity and confidentiality principles.
  • HIPAA: Potential violation of the Security Rule if PHI is compromised, leading to unauthorized changes or loss of data integrity.

Organizations using Mattermost in regulated environments should assess the impact of this vulnerability on their compliance posture and apply patches or mitigations promptly to avoid potential regulatory exposure.

Mitigation Strategies

To mitigate this vulnerability, follow these immediate steps:

  • Upgrade Mattermost to the latest patched version as soon as possible. Refer to the official Mattermost security updates page for the fixed versions.
  • If upgrading is not immediately feasible, restrict access to shared channels with untrusted remote clusters until the upgrade is completed.
  • Monitor shared channel activity for suspicious modifications or deletions of posts, particularly those originating from remote clusters.
  • Review and apply any additional security recommendations provided in the Mattermost advisory MMSA-2026-00689.

For further guidance, consult the Mattermost security updates page linked in the resources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart