Impact
Mattermost versions prior to 11.9.1, 11.8.5, 11.7.8, and 10.11.23 contain a flaw where the system does not verify channel‑member‑management permissions when a playbook run is created. An authenticated member who creates a run and sets the run‑owner field to any user causes that user to be added to a restricted channel without the normal authorization checks. The missing privilege validation (CWE‑862) allows an attacker to introduce arbitrary users into private channels, potentially exposing confidential discussions or enabling lateral movement within the organization.
Affected Systems
The vulnerability affects Mattermost deployments using releases 11.9.0 or earlier, 11.8.4 or earlier, 11.7.7 or earlier, and 10.11.22 or earlier. Any instance where playbook runs are enabled is susceptible, regardless of whether the installation is commercial or open‑source.
Risk and Exploitability
The CVSS score of 7.1 denotes high severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. Attackers must be authenticated as a channel member and have permission to create a playbook run. Based on the description, it is inferred that the exploit path simply involves creating a playbook run and specifying an arbitrary user in the run‑owner field, thereby bypassing channel‑membership checks. Consequently, any legitimate channel member could abuse the flaw without elevated privileges.
OpenCVE Enrichment