Run-state Validation Issue in Mattermost Software by Mattermost
CVE-2026-16046

3.5LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
17 August 2026

What is CVE-2026-16046?

A security vulnerability exists in Mattermost software that fails to enforce proper validation during write operations for completed playbook runs. This oversight allows malicious actors to modify the status, checklists, retrospective content, ownership, and participant details of finalized runs through unauthorized REST and GraphQL API requests, compromising the integrity of the playbook data.

Affected Version(s)

Mattermost 11.7.0 <= 11.7.6

Mattermost 10.11.0 <= 10.11.21

Mattermost 11.9.0

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ilent0
.