Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Mattermost Advisory ID: MMSA-2026-00675
Published: 2026-08-17
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost does not enforce run‑state validation when write operations are performed on finished playbook runs. This flaw allows a run participant to alter the status, checklist items, retrospective content, ownership, and participant list of a completed run via REST or GraphQL API requests. The weakness corresponds to improper authorization controls (CWE‑863), enabling data integrity violations that could affect audit trails and accountability.

Affected Systems

The vulnerability affects Mattermost releases 11.7.x up to and including 11.7.6 and 10.11.x up to and including 10.11.21. Versions 11.9.0, 11.7.7, and 10.11.22 or newer contain the fix and are not impacted.

Risk and Exploitability

The CVSS score of 3.5 indicates low overall severity, but the tweak allows authenticated participants to retroactively modify critical run data, compromising informational integrity. No EPSS score is available, and the issue is not listed in CISA KEV. The likely attack vector is an authenticated user issuing a PATCH request through the Mattermost API, exploiting the missing run‑state check. While the probability of exploitation is not quantified, the impact justifies immediate remediation.

Generated by OpenCVE AI on August 17, 2026 at 15:18 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 11.7.7, 10.11.22 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to a non‑affected release (11.9.0, 11.7.7, or 10.11.22 or later).
  • Review and restrict API permissions for run endpoints, ensuring only users with proper authority can perform write operations on finished runs.
  • Enable detailed audit logging or monitor API traffic to detect unauthorized modifications of run data.

Generated by OpenCVE AI on August 17, 2026 at 15:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 17 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Mattermost Advisory ID: MMSA-2026-00675
Title Missing run-state validation on finished playbook runs
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-17T14:24:14.690Z

Reserved: 2026-07-17T09:43:02.018Z

Link: CVE-2026-16046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T15:16:54.083

Modified: 2026-08-17T15:16:54.083

Link: CVE-2026-16046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:30:06Z

Weaknesses