SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-10542

MEDIUM · CVSS 5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Mattermost versions 11.9.0 and earlier in the 11.9.x, 11.8.x, 11.7.x, and 10.11.x series are vulnerable due to insufficient validation of channel action ownership, enabling channel managers to modify actions in channels they do not own through the channel action update endpoint. This flaw could lead to unauthorized changes and potential data integrity issues within the platform. Organizations using affected Mattermost versions should prioritize patching to mitigate the risk of unauthorized access and action manipulation.

CVE
CVE-2026-10542
Severity
MEDIUM
CVSS
5
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpoint.. Mattermost Advisory ID: MMSA-2026-00692