Access Control Policy Bypass in Mattermost by Mattermost, Inc.
CVE-2026-82920
5.5MEDIUM
What is CVE-2026-82920?
Mattermost versions 11.9.x up to 11.9.0, 11.8.x up to 11.8.4, and 11.7.x up to 11.7.7 are susceptible to a vulnerability that fails to enforce necessary authorization measures on the endpoint responsible for updating access control policies. This can enable a channel or team administrator to erroneously detach a system-assigned Attribute-Based Access Control (ABAC) parent policy by sending a crafted PUT request to /api/v4/access_control_policies with an empty imports list, potentially compromising the security posture of the system.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7