CVE-2026-26304: Permission Bypass in Playbook Run Creation
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify runcreate permission for empty playbookId, which allows team members to create unauthorized runs via the playbook run API. Mattermost Advisory ID: MMSA-2025-00542
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26304?
CVE-2026-26304 has been classified as a critical severity vulnerability due to its impact on unauthorized playbook run creation.
How do I fix CVE-2026-26304?
To fix CVE-2026-26304, upgrade Mattermost to version 11.3.1 or later, or 11.2.3 or later.
Which Mattermost versions are affected by CVE-2026-26304?
CVE-2026-26304 affects Mattermost versions 11.3.x up to 11.3.0 and 11.2.x up to 11.2.2.
What is the impact of CVE-2026-26304?
CVE-2026-26304 allows team members to bypass permission checks and create unauthorized runs, compromising playbook integrity.
Is there a workaround for CVE-2026-26304?
No official workaround exists for CVE-2026-26304; upgrading is the only recommended solution.