SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16046

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 are vulnerable due to inadequate enforcement of run-state validation on write operations for completed playbook runs. This flaw allows participants to alter critical elements such as status, checklists, and ownership of finished runs through REST and GraphQL API requests, potentially leading to unauthorized changes and data integrity issues. Organizations using these Mattermost versions should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-16046
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Mattermost Advisory ID: MMSA-2026-00675

Related CVEs

Other vulnerabilities affecting the same vendor(s)