Access Control Flaw in Mattermost Affecting Team Administrators
CVE-2026-15754

4.2MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
17 August 2026

What is CVE-2026-15754?

An access control flaw exists in Mattermost that permits an authenticated team administrator to unintentionally manipulate the attribute-based access control (ABAC) policy assignments. Specifically, the policy unassign endpoint fails to validate whether the targeted channels still belong to the requesting admin's team. As a result, this vulnerability enables an administrator to alter policy assignments for channels that have been reassigned to different teams, which may lead to unauthorized data exposure and undermine security protocols. For more information, please refer to the Mattermost Advisory ID MMSA-2026-00718.

Affected Version(s)

Mattermost 11.7.0 <= 11.7.6

Mattermost 11.8.0 <= 11.8.3

Mattermost 11.9.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KennySki
.