Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook update
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.1epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api. Mattermost Advisory ID: MMSA-2025-00552
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
Mattermost · MattermostReferences
https://mattermost.com/security-updates