Mattermost Playbook Team Management Bypass Vulnerability

Vulnerability

A vulnerability exists in Mattermost versions 11.5.x through 11.5.1 and 10.11.x through 10.11.13, allowing users with the 'Manage Playbook Configurations' permission to change a playbook's associated team. This issue arises because the application fails to verify if the team ID is being altered during playbook updates. As a result, users can bypass restrictions on managing team members by using the PUT API to make unauthorized changes. Mattermost Advisory ID: MMSA-2025-00552

Impact

Exploitation of this vulnerability could lead to unauthorized changes in playbook team assignments, allowing users to manipulate team management functions without proper permissions.

Remediation

Users can upgrade to Mattermost versions 11.7.0 or 11.7.0 to address this vulnerability.

Added: May 18, 2026, 9:24 AM
Updated: May 18, 2026, 9:24 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
8.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.