Impact
Mattermost versions 11.7.x through 11.7.1, 11.6.x through 11.6.4, and 10.11.x through 10.11.19 allow an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request that references a foreign metric ID. The vulnerability stems from insufficient restriction of metric configuration changes to the playbook being saved, represented by CWE‑639. The primary consequence is the unauthorized modification of playbook settings, which compromises the integrity of playbooks without creating a pathway for remote code execution or data exfiltration.
Affected Systems
Mattermost. Vulnerable versions are 11.6.0–11.6.4, 11.7.0–11.7.1, and 10.11.0–10.11.19.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score shows a probability of exploitation of less than 1%, indicating a very low but nonzero chance. This issue is not cataloged in the CISA KEV list. The attack vector requires an authenticated user with team-level permissions, so the risk is confined to internal teams. Because the alteration affects unrelated playbooks, it can undermine trust and operational consistency within an organization.
OpenCVE Enrichment