cbcvebase.
CVE-2026-4286
published 2026-05-18

CVE-2026-4286: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api. Mattermost Advisory ID: MMSA-2025-00552

Affected

7 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-plugin-playbooks>= 0 < 1.41.1-0.20260213020129-e1d6ec2c94e61.41.1-0.20260213020129-e1d6ec2c94e6
github.commattermost_mattermost_server_v8>= 10.11.0 < 10.11.1410.11.14
github.commattermost_mattermost_server_v8>= 11.5.0 < 11.5.211.5.2
mattermostmattermost10.11.0 – 10.11.13
mattermostmattermost11.5.0 – 11.5.1
mattermostmattermost_server>= 10.11.0 < 10.11.1410.11.14
mattermostmattermost_server>= 11.5.0 < 11.5.211.5.2