Access Control Flaw in Mattermost Affecting Team Administrators
CVE-2026-15754
4.2MEDIUM
What is CVE-2026-15754?
An access control flaw exists in Mattermost that permits an authenticated team administrator to unintentionally manipulate the attribute-based access control (ABAC) policy assignments. Specifically, the policy unassign endpoint fails to validate whether the targeted channels still belong to the requesting admin's team. As a result, this vulnerability enables an administrator to alter policy assignments for channels that have been reassigned to different teams, which may lead to unauthorized data exposure and undermine security protocols. For more information, please refer to the Mattermost Advisory ID MMSA-2026-00718.
Affected Version(s)
Mattermost 11.7.0 <= 11.7.6
Mattermost 11.8.0 <= 11.8.3
Mattermost 11.9.0