PT-2026-25810 · Mattermost · Mattermost+1

0X7Oda7123

·

Publicado

2026-02-13

·

Atualizado

2026-03-27

·

CVE-2026-26304

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 11.2.0 through 11.2.2 Mattermost versions 11.3.0
Description The software does not properly verify the run create permission when a playbookId is empty. This allows team members to create unauthorized runs through the playbook run API. The vulnerable component is located in github.com/mattermost/mattermost-plugin-playbooks. The API endpoint used for exploitation is the playbook run API. The vulnerable parameter is playbookId.
Recommendations Update Mattermost to a version later than 11.2.2. Update Mattermost to a version later than 11.3.0.

Correção

Improper Access Control

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-06557
CVE-2026-26304
GHSA-4PMX-622H-X359
GO-2026-4812
SUSE-SU-2026:1135-1

Produtos afetados

Mattermost
Mattermost Playbooks Plugin