SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-8821

HIGH · CVSS 7.1

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Mattermost versions 11.9.0 and earlier, along with 11.8.4, 11.7.7, and 10.11.22, are vulnerable due to inadequate validation of channel member-management permissions during playbook run creation. This flaw allows authenticated users to exploit the run owner field to add unauthorized users to restricted channels, potentially leading to unauthorized access to sensitive information. Organizations using these versions should prioritize remediation to safeguard their channel integrity and prevent unauthorized access.

CVE
CVE-2026-8821
Severity
HIGH
CVSS
7.1
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run owner field.. Mattermost Advisory ID: MMSA-2026-00677