Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which allows team members to create unauthorized runs via the playbook run API. Mattermost Advisory ID: MMSA-2025-00542
{ "versions": [ { "introduced": "11.2.0" }, { "fixed": "11.2.3" }, { "introduced": "11.3.0" }, { "fixed": "11.3.1" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26304.json"