Improper Permission Validation in Mattermost Channels Affects User Management
CVE-2026-8821

7.1HIGH

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
14 September 2026

What is CVE-2026-8821?

In various versions of Mattermost, an oversight in the validation of member-management permissions during the creation of playbook runs can be exploited. Specifically, authenticated members of a channel might gain the ability to add arbitrary users to restricted channels by manipulating the run owner field. This vulnerability poses significant risks to user privacy and channel security, urging administrators to upgrade their Mattermost installations promptly. For more detailed information, please refer to the Mattermost Advisory ID: MMSA-2026-00677.

Affected Version(s)

Mattermost 11.9.0

Mattermost 11.8.0 <= 11.8.4

Mattermost 11.7.0 <= 11.7.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ilent0
.