Cross-Site Request Forgery in Mattermost Access Control Policy Management
CVE-2026-27659

4.6MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
25 March 2026

What is CVE-2026-27659?

The Mattermost platform is at risk due to a Cross-Site Request Forgery vulnerability that affects specific versions of its software. This weakness occurs in the API endpoint responsible for managing access control policies. Attackers can exploit this flaw to craft malicious requests that may trick an administrator into inadvertently activating or deactivating policy changes. It is essential for organizations using affected versions of Mattermost to implement the recommended patches and adhere to security best practices to mitigate potential unauthorized changes in access controls.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Mattermost 11.2.0 <= 11.2.2

Mattermost 10.11.0 <= 10.11.10

Mattermost 11.4.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Rogers
.