Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run property-management access to crash the Playbooks plugin via a REST request referencing a property field that belongs to a different run. Mattermost Advisory ID: MMSA-2026-00684
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Application Crash)
Action: Immediate Patch
AI Analysis

Impact

Mattermost versions 11.9.x through 10.11.x lack validation that a property field belongs to the run specified for an update. An authenticated user with run property‑management rights can craft a REST request that targets a property field belonging to another run, causing the Playbooks plugin to crash. The flaw is a classic missing ownership validation, classified as CWE‑639, and can lead to loss of service for users of the affected process.

Affected Systems

All Mattermost installations running the Playbooks plugin on the following versions are impacted: 11.9.0 and earlier (up to 11.9.0), 11.8.4 and earlier, 11.7.7 and earlier, as well as 10.11.22 and earlier. Updating to 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or any later release eliminates the vulnerability.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate severity. EPSS is not available, so there is no quantified likelihood of exploitation, but the application crash could affect service availability if triggered. The vulnerability is not listed in the CISA KEV catalog, which suggests no known public exploits at this time. It is inferred that the attack vector requires network or internal access to the REST API and authenticated possession of run property‑management privileges. Without these prerequisites, exploitation is unlikely. Nonetheless, any authenticated actor who can access the endpoint can cause the Cloud or on‑premise plugin to terminate, potentially disrupting teamwork workflows.

Generated by OpenCVE AI on September 15, 2026 at 14:28 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Install Mattermost 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or any later release to apply the validation fix.
  • If upgrading is not immediately feasible, restrict or remove the Playbooks plugin’s REST endpoint that processes property field updates, or limit the run property‑management permission to trusted users only.
  • Enable audit logging for property‑update API calls and monitor for attempts to modify fields belonging to runs other than the one targeted to detect misuse before it can cause a crash.

Generated by OpenCVE AI on September 15, 2026 at 14:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run property-management access to crash the Playbooks plugin via a REST request referencing a property field that belongs to a different run. Mattermost Advisory ID: MMSA-2026-00684
Title Missing property field ownership validation in Playbooks run property update endpoint
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T11:19:44.536Z

Reserved: 2026-05-28T08:47:31.086Z

Link: CVE-2026-9812

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:26.815Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:08.393

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-9812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key