CVE-2026-8821
moderateMissing Authorization in Mattermost Playbooks Allows Adding Users to Restricted Channels
Mattermost versions 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22 fail to validate channel member-management permissions when a playbook run is created (CWE-862, missing authorization). An attacker with only a low-privilege authenticated account who is already a member of a channel can create a playbook run and set an arbitrary user as the run owner, which effectively adds that user to a restricted channel without the attacker having permission to manage channel members. Successful exploitation grants unauthorized membership in private channels, exposing confidential conversations and shared files, which is reflected in the high CVSS 3.1 score of 7.1 (confidentiality high, integrity low). The issue affects self-hosted Mattermost deployments running the listed versions; Mattermost Cloud instances are patched by the vendor. There is no known public proof of concept, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported.
What to do: Upgrade to the latest patch release in your branch (any release newer than 11.9.0, 11.8.4, 11.7.7, or 10.11.22, or a currently supported version). Until patched, review which users can create playbook runs and audit channel membership changes and playbook run owner assignments in system/audit logs for unauthorized additions to restricted channels. Mattermost Cloud customers are covered by vendor patching, but self-hosted administrators should verify their server version and apply the update promptly.
| Mattermost | 11.9.x <= 11.9.0 |
| Mattermost | 11.8.x <= 11.8.4 |
| Mattermost | 11.7.x <= 11.7.7 |
| Mattermost | 10.11.x <= 10.11.22 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run owner field.. Mattermost Advisory ID: MMSA-2026-00677
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.