Executive brief
Mattermost Playbooks, a task automation and workflow management plugin, fails to properly validate which run a property field belongs to before allowing updates. An authenticated user with property-management permissions can exploit this to crash the Playbooks plugin by sending a REST request with a property field from a different run, causing service disruption.
Technical details
This is an authorization/validation bypass vulnerability in the Mattermost Playbooks plugin's property field management API. The vulnerable component fails to verify that a property field belongs to the specified run before processing update requests. The attack requires network access to the REST API and valid authentication credentials with run property-management access. An attacker can trigger a denial-of-service condition by referencing a property field from an unrelated run, crashing the Playbooks plugin. Patches are available in versions 11.9.1+, 11.8.5+, 11.7.8+, and 10.11.23+.
Affected products
- Mattermost Playbooks 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Patches available: 11.9.1+, 11.8.5+, 11.7.8+, 10.11.23+