Executive brief
Mattermost Server, a team collaboration platform, contains an authorization flaw in its playbook creation feature. An authenticated user who is a member of a restricted channel can exploit this to add any other user to that channel without proper permission checks, potentially exposing sensitive team communications to unauthorized individuals.
Technical details
Mattermost Server fails to validate channel member-management permissions during playbook run creation. The vulnerability exists in the run owner field assignment logic, where the application does not properly check whether the authenticated user has authorization to add members to the target channel. An authenticated channel member can exploit this by creating or modifying a playbook run and setting the owner field to an arbitrary user, thereby adding that user to a restricted channel. This is a permission validation bypass requiring authentication and channel membership. The vulnerability affects multiple versions: 11.9.0 and earlier in the 11.9.x line, 11.8.4 and earlier in 11.8.x, 11.7.7 and earlier in 11.7.x, and 10.11.22 and earlier in 10.11.x; patched versions are available.
Affected products
- Mattermost Mattermost Server 11.9.0 and earlier in 11.9.x; 11.8.4 and earlier in 11.8.x; 11.7.7 and earlier in 11.7.x; 10.11.22 and earlier in 10.11.x
Timeline
- 2026-09-14: disclosed: CVE-2026-8821 published on NVD