CyberRota Analysis
AI-GeneratedMattermost versions 11.9.0 and earlier, along with 11.8.4, 11.7.7, and 10.11.22, are vulnerable due to inadequate validation of channel member-management permissions during playbook run creation. This flaw allows authenticated users to exploit the run owner field to add unauthorized users to restricted channels, potentially leading to unauthorized access to sensitive information. Organizations using these versions should prioritize remediation to safeguard their channel integrity and prevent unauthorized access.
Original NVD Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run owner field.. Mattermost Advisory ID: MMSA-2026-00677