CVE-2026-6062: IDOR in Jira plugin subscription edit endpoint
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subscription before applying edits which allows an authenticated attacker to hijack subscriptions from channels they have no access to via a crafted PUT request to the subscription edit endpoint.. Mattermost Advisory ID: MMSA-2026-00650
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0Patch MMSA-2026-00650 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.1Patch MMSA-2026-00650 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.3Patch MMSA-2026-00650 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.6Patch MMSA-2026-00650 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.18Patch MMSA-2026-00650
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6062?
The severity of CVE-2026-6062 is medium with a score of 6.4.
How do I fix CVE-2026-6062?
To fix CVE-2026-6062, update Mattermost to a version that addresses the IDOR vulnerability in the subscription edit endpoint.
What does CVE-2026-6062 exploit?
CVE-2026-6062 exploits the lack of validation for channel ownership in the subscription edit endpoint.
Who is affected by CVE-2026-6062?
Mattermost users running versions 11.7.x, 11.6.x, 11.5.x, and 10.11.x up to their specified limits are affected by CVE-2026-6062.
What type of attack is associated with CVE-2026-6062?
CVE-2026-6062 is associated with an authenticated attack exploiting inadequate channel ownership validation to hijack subscriptions.