CVE-2026-6541: Unscoped updates to other playbooks' metric configuration
Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6541?
The severity of CVE-2026-6541 is medium with a CVSS score of 4.3.
What systems are affected by CVE-2026-6541?
CVE-2026-6541 affects Mattermost versions 11.7.x up to 11.7.1, 11.6.x up to 11.6.4, and 10.11.x up to 10.11.19.
How can I fix CVE-2026-6541?
To fix CVE-2026-6541, you should upgrade Mattermost to a version higher than the affected versions listed.
What does CVE-2026-6541 allow an attacker to do?
CVE-2026-6541 allows an authenticated user with team access to alter another user's playbook metric settings.
When was CVE-2026-6541 published?
CVE-2026-6541 was published on July 13, 2026.