CVE-2026-4055: Insufficient permission validation on cross-team playbook run creation
Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level runcreate permission against the target team when creating a playbook run which allows an authenticated team member to create runs in teams where they lack permission via specifying a different team ID in the run creation API request. Mattermost Advisory ID: MMSA-2026-00629
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.14 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4055?
CVE-2026-4055 has a medium severity score of 4.3.
How do I fix CVE-2026-4055?
To remediate CVE-2026-4055, update Mattermost to versions 11.6.0, 11.5.2, 10.11.14, 11.4.4 or higher.
What does CVE-2026-4055 involve?
CVE-2026-4055 involves insufficient permission validation on cross-team playbook run creation in Mattermost.
Who is affected by CVE-2026-4055?
Authenticated team members using Mattermost versions 11.5.x <= 11.5.1 are affected by CVE-2026-4055.
What could an attacker do with CVE-2026-4055?
An attacker could create playbook runs in teams where they lack permission by specifying a different team ID in the API request.