CVE-2026-4286: Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook update
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{teamid}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api. Mattermost Advisory ID: MMSA-2025-00552
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4286?
CVE-2026-4286 is considered to have a high severity due to its potential for unauthorized access and team management exploits.
How do I fix CVE-2026-4286?
To fix CVE-2026-4286, update Mattermost to the latest version above 11.5.1 or 10.11.13 and ensure proper validation of team IDs when modifying playbooks.
What versions of Mattermost are affected by CVE-2026-4286?
Mattermost versions 11.5.0 to 11.5.1 and 10.11.0 to 10.11.13 are affected by CVE-2026-4286.
What impact does CVE-2026-4286 have on user permissions?
CVE-2026-4286 allows unauthorized removal of member access without proper validation during playbook updates.
Is the Mattermost Playbooks Plugin vulnerable to CVE-2026-4286?
Yes, the Mattermost Playbooks Plugin is vulnerable to CVE-2026-4286 due to a lack of team ID validation.