Access Control Policy Bypass in Mattermost by Mattermost, Inc.
CVE-2026-82920

5.5MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82920?

Mattermost versions 11.9.x up to 11.9.0, 11.8.x up to 11.8.4, and 11.7.x up to 11.7.7 are susceptible to a vulnerability that fails to enforce necessary authorization measures on the endpoint responsible for updating access control policies. This can enable a channel or team administrator to erroneously detach a system-assigned Attribute-Based Access Control (ABAC) parent policy by sending a crafted PUT request to /api/v4/access_control_policies with an empty imports list, potentially compromising the security posture of the system.

Affected Version(s)

Mattermost 11.9.0

Mattermost 11.8.0 <= 11.8.4

Mattermost 11.7.0 <= 11.7.7

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kiwi_71
.