Executive brief
Mattermost, a collaboration platform for teams, contains a flaw in its Playbooks feature. An authorized user could bypass security restrictions to create playbook runs in teams they do not belong to. This could lead to unauthorized activity or organizational disruption within teams where the user should not have access.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Mattermost Server versions 11.5.x <= 11.5.1. The application fails to validate the 'run_create' permission against the specific target team during a playbook run creation request. An authenticated attacker can exploit this by manually specifying a different team ID in the API request, allowing them to initiate playbook runs in teams where they lack the necessary privileges. The issue is addressed in versions 11.5.2, 11.6.0, and 10.11.14.
Affected products
- Mattermost Mattermost Server 11.5.0 - 11.5.1
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory