Junglewise Threat Intelligence

CVE-2026-6541: Mattermost authorization bypass in Playbook metric configuration

CVE-2026-6541 · Severity: medium · CVSS 4.3 · Published 2026-07-13

Technologies: Mattermost. Vendors: Mattermost.

Executive brief

Mattermost, a collaboration platform for incident response and team communication, contains a security flaw in its Playbooks feature. An authorized user on a team can modify the metric settings of playbooks belonging to other users by sending a specially crafted request. While this does not allow for data theft, it could lead to unauthorized changes in how team performance and incident metrics are tracked and reported.

Technical details

An authorization bypass (CWE-639) exists in Mattermost Playbooks due to insufficient validation of metric IDs during import or update operations. An authenticated attacker with team access can supply a 'foreign' metric ID in a crafted request to modify the metric configuration of a playbook they do not own. The vulnerability is reachable over the network and requires low privileges (authenticated user). The impact is limited to integrity, specifically the unauthorized modification of playbook metric settings. The issue is addressed in versions 11.8.0, 11.7.2, 11.6.5, and 10.11.20.

Affected products

  • Mattermost Mattermost 11.7.0 - 11.7.1, 11.6.0 - 11.6.4, 10.11.0 - 10.11.19

Timeline

  • 2026-07-13: advisory
  • 2026-07-13: disclosed

References

Related threats