CVE-2026-10106
Last modified
CVE-2026-10106 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost Server | >= 10.11.0, < 10.11.20 |
| Mattermost | Mattermost Server | >= 11.6.0, < 11.6.5 |
| Mattermost | Mattermost Server | >= 11.7.0, < 11.7.3 |
References
- https://mattermost.com/security-updatesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-10106?
How severe is CVE-2026-10106?
How do I fix CVE-2026-10106?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1010A stored cross-site scripting (XSS) vulnerability exists in …5.4
- CVE-2026-10100The Simple Custom Login Page plugin for WordPress is vulnera…4.4
- CVE-2026-10101ACM/MCE assisted-service writes raw referenced pull-secret c…6.3
- CVE-2026-10103Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.1…4.3
- CVE-2026-10104The Product Video Gallery for Woocommerce plugin for WordPre…4.4
- CVE-2026-10105agno 2.6.5 contains a SQL injection vulnerability in the Cli…8.7
- CVE-2026-10107MoviePilot v2 contains a server-side request forgery vulnera…7.7
- CVE-2026-10108xiaomusic v0.5.7 contains an unauthenticated path traversal …8.7
- CVE-2026-10109IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is …9.8
- CVE-2026-1011A stored cross-site scripting (XSS) vulnerability exists in …6.1
- CVE-2026-10110A vulnerability was detected in code-projects Student Detail…7.3
- CVE-2026-10111A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM…7.3
Are you affected by CVE-2026-10106?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
