Mattermost · Mattermost · CVE-2026-9708
**Name of the Vulnerable Software and Affected Versions**
Mattermost versions 11.7.0 through 11.7.2
Mattermost versions 11.6.0 through 11.6.4
Mattermost versions 10.11.0 through 10.11.19
**Description**
An issue exists where the system fails to validate whether an assigned incoming webhook user has the necessary access to the target team or channel. This allows a requester with webhook management permissions to create posts or direct messages attributed to another user by using crafted incoming webhook configurations and payloads.
**Recommendations**
Update Mattermost versions 11.7.0 through 11.7.2 to a version newer than 11.7.2.
Update Mattermost versions 11.6.0 through 11.6.4 to a version newer than 11.6.4.
Update Mattermost versions 10.11.0 through 10.11.19 to a version newer than 10.11.19.