Improper Permission Validation in Mattermost Channels Affects User Management
CVE-2026-8821
7.1HIGH
What is CVE-2026-8821?
In various versions of Mattermost, an oversight in the validation of member-management permissions during the creation of playbook runs can be exploited. Specifically, authenticated members of a channel might gain the ability to add arbitrary users to restricted channels by manipulating the run owner field. This vulnerability poses significant risks to user privacy and channel security, urging administrators to upgrade their Mattermost installations promptly. For more detailed information, please refer to the Mattermost Advisory ID: MMSA-2026-00677.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7