ZeroHour

CVE-2026-8821

moderate

Missing Authorization in Mattermost Playbooks Allows Adding Users to Restricted Channels

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

Mattermost versions 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22 fail to validate channel member-management permissions when a playbook run is created (CWE-862, missing authorization). An attacker with only a low-privilege authenticated account who is already a member of a channel can create a playbook run and set an arbitrary user as the run owner, which effectively adds that user to a restricted channel without the attacker having permission to manage channel members. Successful exploitation grants unauthorized membership in private channels, exposing confidential conversations and shared files, which is reflected in the high CVSS 3.1 score of 7.1 (confidentiality high, integrity low). The issue affects self-hosted Mattermost deployments running the listed versions; Mattermost Cloud instances are patched by the vendor. There is no known public proof of concept, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported.

What to do: Upgrade to the latest patch release in your branch (any release newer than 11.9.0, 11.8.4, 11.7.7, or 10.11.22, or a currently supported version). Until patched, review which users can create playbook runs and audit channel membership changes and playbook run owner assignments in system/audit logs for unauthorized additions to restricted channels. Mattermost Cloud customers are covered by vendor patching, but self-hosted administrators should verify their server version and apply the update promptly.

Affected
Mattermost11.9.x <= 11.9.0
Mattermost11.8.x <= 11.8.4
Mattermost11.7.x <= 11.7.7
Mattermost10.11.x <= 10.11.22
Estimated exposure
moderate≈ a few thousand internet-exposed Mattermost servers out of an estimated tens of thousands of self-hosted deployments — Public internet scans (Shodan/Censys) typically enumerate a few thousand directly reachable Mattermost instances, while the majority of Mattermost deployments are self-hosted behind corporate firewalls or VPNs, limiting remotely reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run owner field.. Mattermost Advisory ID: MMSA-2026-00677

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.