Vulnerability GHSA-mxq2-5jpg-7474

Medium Risk
MEDIUM RISK
CVSS Score: 6.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
June 22, 2026 at 03:30 PM UTC
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
v10.11.0+incompatible - v10.11.17+incompatible and v11.5.0+incompatible - v11.5.5+incompatible and v11.6.0+incompatible - v11.6.2+incompatible and v11.7.0+incompatible
v10.11.0+incompatible - v10.11.17+incompatible and v11.5.0+incompatible - v11.5.5+incompatible and v11.6.0+incompatible - v11.6.2+incompatible and v11.7.0+incompatible

Summary

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

Details

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subscription before applying edits which allows an authenticated attacker to hijack subscriptions from channels they have no access to via a crafted PUT request to the subscription edit endpoint.. Mattermost Advisory ID: MMSA-2026-00650

Timeline

Published
2 months ago
June 22, 2026 at 03:30 PM UTC
Last Modified
1 day ago
September 15, 2026 at 08:00 PM UTC