SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-6541

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.x up to 11.7.1, 11.6.x up to 11.6.4, and 10.11.x up to 10.11.19 are vulnerable due to insufficient restrictions on metric configuration changes, allowing authenticated users with team access to modify another user's playbook metrics through crafted requests. This could lead to unauthorized alterations of critical playbook settings, potentially impacting team workflows and data integrity. Organizations using these Mattermost versions should prioritize this vulnerability to mitigate risks associated with unauthorized access and manipulation of playbook metrics.

CVE
CVE-2026-6541
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653

Related CVEs

Other vulnerabilities affecting the same vendor(s)