Junglewise Threat Intelligence

CVE-2026-9812: Mattermost Playbooks property field validation bypass

CVE-2026-9812 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Vendors: Mattermost.

Executive brief

Mattermost Playbooks, a task automation and workflow management plugin, fails to properly validate which run a property field belongs to before allowing updates. An authenticated user with property-management permissions can exploit this to crash the Playbooks plugin by sending a REST request with a property field from a different run, causing service disruption.

Technical details

This is an authorization/validation bypass vulnerability in the Mattermost Playbooks plugin's property field management API. The vulnerable component fails to verify that a property field belongs to the specified run before processing update requests. The attack requires network access to the REST API and valid authentication credentials with run property-management access. An attacker can trigger a denial-of-service condition by referencing a property field from an unrelated run, crashing the Playbooks plugin. Patches are available in versions 11.9.1+, 11.8.5+, 11.7.8+, and 10.11.23+.

Affected products

  • Mattermost Playbooks 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Patches available: 11.9.1+, 11.8.5+, 11.7.8+, 10.11.23+

References