CVE-2026-15754
Received Received - Intake

Access Control Bypass in Mattermost via Policy Unassign

Vulnerability report for CVE-2026-15754, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ABAC (attribute-based access control) policy assignments from channels outside their team via the policy unassign API after a channel has been moved to another team.. Mattermost Advisory ID: MMSA-2026-00718

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.7.6 (inc)
mattermost mattermost to 11.8.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Mattermost versions between 11.7.0 and 11.7.6, and 11.8.0 and 11.8.3. It involves an access control flaw where a team administrator can remove ABAC policy assignments from channels that have been moved to another team. The issue occurs because the unassign endpoint does not re-validate if the channel still belongs to the administrator's team.

Detection Guidance

Check Mattermost server logs for unauthorized policy unassign API calls. Look for requests to /api/v4/policies/unassign with admin privileges targeting channels outside the admin's team. Verify Mattermost version is below 11.7.6 or 11.8.3.

Impact Analysis

An authenticated team administrator could misuse this flaw to remove access control policies from channels outside their team. This could lead to unauthorized access or unintended permissions being granted to users in other teams.

Compliance Impact

The vulnerability allows an authenticated team administrator to remove ABAC policy assignments from channels outside their team after a channel is moved. This could lead to unauthorized access or data exposure, potentially violating compliance requirements for GDPR (data protection) and HIPAA (healthcare data privacy).

Mitigation Strategies

Upgrade Mattermost to version 11.7.6 or 11.8.3 or later. Review and revoke any unauthorized policy unassign actions performed by team administrators. Monitor API logs for suspicious unassign operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15754. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart