Back

MEDIUM

Unscoped updates to other playbooks' metric configuration

Published Jul 13, 2026

Description

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653

Affected products

Remediation

Vendor solution

Update Mattermost to versions 11.8.0, 11.7.2, 11.6.5, 10.11.20 or higher.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Jul 13, 2026
Updated Jul 13, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Jul 13, 2026
NVD
Status Analyzed
Modified Jul 13, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Mattermost
Published Jul 13, 2026
Updated Jul 13, 2026
Exploited since n/a
EUVD-2026-43341