CyberRota Analysis
AI-GeneratedMattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 are vulnerable due to inadequate enforcement of run-state validation on write operations for completed playbook runs. This flaw allows participants to alter critical elements such as status, checklists, and ownership of finished runs through REST and GraphQL API requests, potentially leading to unauthorized changes and data integrity issues. Organizations using these Mattermost versions should prioritize remediation to mitigate the risk of exploitation.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Mattermost Advisory ID: MMSA-2026-00675
Related CVEs
Other vulnerabilities affecting the same vendor(s)