What is CVE-2026-16046?
Mattermost versions up to 11.7.6 and 10.11.21 fail to enforce run-state validation on finished playbook runs. This allows a run participant to modify status, checklists, ownership, and participants on completed runs via REST/GraphQL API. Updating to the latest Mattermost version immediately is strongly recommended.
Azərbaycanca: Mattermost-un 11.7.6 və 10.11.21-ə qədər olan versiyalarında başa çatmış playbook run-ları üçün run-state validation çatışmazlığı mövcuddur. Bu boşluq iştirakçıya REST/GraphQL API vasitəsilə tamamlanmış run-ın statusu, yoxlama siyahıları, sahiblik və iştirakçılarını dəyişməyə imkan verir. Dərhal Mattermost-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Mattermost
FAQ2
Is it possible to modify data of a finished playbook run?
Yes, due to CVE-2026-16046, a run participant can modify the status, checklists, ownership, and participants of a completed run via the REST/GraphQL API.
Which versions of Mattermost are affected by this vulnerability?
Mattermost versions up to 11.7.6 and 10.11.21 are affected by this run-state validation failure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.