Impact
Mattermost does not enforce run‑state validation when write operations are performed on finished playbook runs. This flaw allows a run participant to alter the status, checklist items, retrospective content, ownership, and participant list of a completed run via REST or GraphQL API requests. The weakness corresponds to improper authorization controls (CWE‑863), enabling data integrity violations that could affect audit trails and accountability.
Affected Systems
The vulnerability affects Mattermost releases 11.7.x up to and including 11.7.6 and 10.11.x up to and including 10.11.21. Versions 11.9.0, 11.7.7, and 10.11.22 or newer contain the fix and are not impacted.
Risk and Exploitability
The CVSS score of 3.5 indicates low overall severity, but the tweak allows authenticated participants to retroactively modify critical run data, compromising informational integrity. No EPSS score is available, and the issue is not listed in CISA KEV. The likely attack vector is an authenticated user issuing a PATCH request through the Mattermost API, exploiting the missing run‑state check. While the probability of exploitation is not quantified, the impact justifies immediate remediation.
OpenCVE Enrichment