CVE-2026-15754

Summary

Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ABAC (attribute-based access control) policy assignments from channels outside their team via the policy unassign API after a channel has been moved to another team.. Mattermost Advisory ID: MMSA-2026-00718

Affected Software

VendorProductVersion RangeStatus
MattermostMattermost11.7.0 <= 11.7.6affected
MattermostMattermost11.8.0 <= 11.8.3affected
MattermostMattermost11.9.0unaffected
MattermostMattermost11.7.7unaffected
MattermostMattermost11.8.4unaffected

Weaknesses

  • CWE-863: CWE-863: Incorrect Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References