Description
Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653
Published: 2026-07-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost versions 11.7.x through 11.7.1, 11.6.x through 11.6.4, and 10.11.x through 10.11.19 allow an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request that references a foreign metric ID. The vulnerability stems from insufficient restriction of metric configuration changes to the playbook being saved, represented by CWE‑639. The primary consequence is the unauthorized modification of playbook settings, which compromises the integrity of playbooks without creating a pathway for remote code execution or data exfiltration.

Affected Systems

Mattermost. Vulnerable versions are 11.6.0–11.6.4, 11.7.0–11.7.1, and 10.11.0–10.11.19.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. The EPSS score shows a probability of exploitation of less than 1%, indicating a very low but nonzero chance. This issue is not cataloged in the CISA KEV list. The attack vector requires an authenticated user with team-level permissions, so the risk is confined to internal teams. Because the alteration affects unrelated playbooks, it can undermine trust and operational consistency within an organization.

Generated by OpenCVE AI on July 31, 2026 at 11:39 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.8.0, 11.7.2, 11.6.5, 10.11.20 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to version 11.8.0, 11.7.2, 11.6.5, or 10.11.20 or higher, which contains the fix for this issue.
  • Configure import and update endpoints to validate metric IDs belong to the owner playbook or are correctly scoped so that cross‑playbook alterations are rejected.
  • Limit the use of the playbook import/update feature to trusted users and perform regular audits of playbook metrics to detect unauthorized changes.

Generated by OpenCVE AI on July 31, 2026 at 11:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 13 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653
Title Unscoped updates to other playbooks' metric configuration
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-13T13:09:10.482Z

Reserved: 2026-04-17T17:54:44.831Z

Link: CVE-2026-6541

cve-icon Vulnrichment

Updated: 2026-07-13T13:09:07.188Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key