Impact
Mattermost versions 11.9.x through 10.11.x lack validation that a property field belongs to the run specified for an update. An authenticated user with run property‑management rights can craft a REST request that targets a property field belonging to another run, causing the Playbooks plugin to crash. The flaw is a classic missing ownership validation, classified as CWE‑639, and can lead to loss of service for users of the affected process.
Affected Systems
All Mattermost installations running the Playbooks plugin on the following versions are impacted: 11.9.0 and earlier (up to 11.9.0), 11.8.4 and earlier, 11.7.7 and earlier, as well as 10.11.22 and earlier. Updating to 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or any later release eliminates the vulnerability.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity. EPSS is not available, so there is no quantified likelihood of exploitation, but the application crash could affect service availability if triggered. The vulnerability is not listed in the CISA KEV catalog, which suggests no known public exploits at this time. It is inferred that the attack vector requires network or internal access to the REST API and authenticated possession of run property‑management privileges. Without these prerequisites, exploitation is unlikely. Nonetheless, any authenticated actor who can access the endpoint can cause the Cloud or on‑premise plugin to terminate, potentially disrupting teamwork workflows.
OpenCVE Enrichment