Mattermost · Mattermost · CVE-2026-10106
**Name of the Vulnerable Software and Affected Versions**
Mattermost versions 11.7.0 through 11.7.2
Mattermost versions 11.6.0 through 11.6.4
Mattermost versions 10.11.0 through 10.11.19
**Description**
An authenticated user without access to a private channel can trigger interactive post actions on posts within that channel. This occurs because the system fails to verify that the channel referenced in an action cookie matches the channel of the target post, allowing the use of a cookie obtained from any accessible channel.
**Recommendations**
Update Mattermost versions 11.7.0 through 11.7.2 to a version newer than 11.7.2.
Update Mattermost versions 11.6.0 through 11.6.4 to a version newer than 11.6.4.
Update Mattermost versions 10.11.0 through 10.11.19 to a version newer than 10.11.19.