SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-9812

MEDIUM · CVSS 6.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to inadequate validation of property fields during updates, allowing authenticated users with property-management access to crash the Playbooks plugin through a malicious REST request. This vulnerability could lead to service disruptions and impact the availability of the Playbooks functionality. Organizations using affected Mattermost versions should prioritize remediation to mitigate potential operational impacts.

CVE
CVE-2026-9812
Severity
MEDIUM
CVSS
6.5
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run property-management access to crash the Playbooks plugin via a REST request referencing a property field that belongs to a different run. Mattermost Advisory ID: MMSA-2026-00684