CVE-2023-6547: Mattermost Server

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 

Affected products

  • Mattermost Mattermost Server: up to and including 8.1.5; from 9.2.0, up to and including 9.2.1

Published 2023-12-12. Last modified 2026-06-17.