CVE-2026-8821: Playbooks run owner channel membership permission bypass
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run owner field.. Mattermost Advisory ID: MMSA-2026-00677
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.11.23
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who is already a member of the target channel can exploit it. The issue affects restricted channels when the user lacks the normal permission to manage channel membership.
What access does an attacker gain through exploitation?
The attacker can add an arbitrary user to the restricted channel by setting that user as the playbook run owner during run creation. This can expose the channel’s contents to the added user and gives the attacker a way to bypass member-management controls.
Which Mattermost releases are affected?
Affected releases are Mattermost 11.9.0 and earlier 11.9.x releases, 11.8.4 and earlier 11.8.x releases, 11.7.7 and earlier 11.7.x releases, and 10.11.22 and earlier 10.11.x releases.