CyberRota Analysis
AI-GeneratedMattermost versions 11.7.x up to 11.7.1, 11.6.x up to 11.6.4, and 10.11.x up to 10.11.19 are vulnerable due to insufficient restrictions on metric configuration changes, allowing authenticated users with team access to modify another user's playbook metrics through crafted requests. This could lead to unauthorized alterations of critical playbook settings, potentially impacting team workflows and data integrity. Organizations using these Mattermost versions should prioritize this vulnerability to mitigate risks associated with unauthorized access and manipulation of playbook metrics.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653
Related CVEs
Other vulnerabilities affecting the same vendor(s)