PT-2026-25810 · Mattermost · Mattermost+1

0X7Oda7123

·

Published

2026-02-13

·

Updated

2026-03-27

·

CVE-2026-26304

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 11.2.0 through 11.2.2 Mattermost versions 11.3.0
Description The software does not properly verify the run create permission when a playbookId is empty. This allows team members to create unauthorized runs through the playbook run API. The vulnerable component is located in github.com/mattermost/mattermost-plugin-playbooks. The API endpoint used for exploitation is the playbook run API. The vulnerable parameter is playbookId.
Recommendations Update Mattermost to a version later than 11.2.2. Update Mattermost to a version later than 11.3.0.

Fix

Improper Access Control

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-06557
CVE-2026-26304
GHSA-4PMX-622H-X359
GO-2026-4812
SUSE-SU-2026:1135-1

Affected Products

Mattermost
Mattermost Playbooks Plugin