Back

MEDIUM

Incoming webhook user attribution via unvalidated webhook owner

Published Jul 13, 2026

Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

Affected products

Remediation

Vendor solution

Update Mattermost to versions 11.8.0, 11.7.3, 11.6.5, 10.11.20 or higher.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Jul 13, 2026
Updated Jul 13, 2026
Reserved May 27, 2026
CISA Vulnrichment
Updated Jul 13, 2026
NVD
Status Analyzed
Modified Jul 13, 2026
Red Hat
Severity n/a
Public date n/a