Property Management Flaw in Mattermost Affects Multiple Versions
CVE-2026-9812
6.5MEDIUM
What is CVE-2026-9812?
Mattermost includes a vulnerability where versions 10.11.22 and 11.7.x through 11.9.x fail to properly validate property fields during updates. This flaw allows an authenticated user with property-management access to inadvertently crash the Playbooks plugin by referencing a property field from a different run via a REST request. This could lead to significant disruptions in service and necessitates prompt attention to ensure secure functionality.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7