CVE-2026-16046: Missing run-state validation on finished playbook runs
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Mattermost Advisory ID: MMSA-2026-00675
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.7 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16046?
The severity of CVE-2026-16046 is classified as low with a CVSS score of 3.5.
What does CVE-2026-16046 exploit?
CVE-2026-16046 exploits the lack of run-state validation on finished playbook runs, allowing unauthorized modifications.
How do I fix CVE-2026-16046?
To fix CVE-2026-16046, update Mattermost to versions higher than 11.7.6 or 10.11.21.
Who is affected by CVE-2026-16046?
Users of Mattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 are affected by CVE-2026-16046.
What are the implications of CVE-2026-16046?
The implications of CVE-2026-16046 include the potential for unauthorized changes to completed playbook runs by run participants.