Impact
The unassign endpoint in Mattermost does not re‑validate that the channels targeted by a policy removal request belong to the requesting team. This oversight allows an authenticated team administrator to remove ABAC policy assignments from channels that have been moved to another team, effectively erasing those policy bindings for unauthorized teams. The breach does not grant code execution or denial of service; it simply compromises the integrity of ABAC permission assignments for cross‑team channels.
Affected Systems
Mattermost Mattermost is affected in releases 11.7.0 through 11.7.6 inclusive, and 11.8.0 through 11.8.3 inclusive. The fix is available in Mattermost 11.7.7, 11.8.4, and 11.9.0 or later.
Risk and Exploitability
With a CVSS score of 4.2 the vulnerability is low to moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation risk. The attack vector is inferred to be an authenticated request to the policy unassign API performed by a team administrator after a channel has been moved to a different team. No additional privileges or external exploits are required beyond the normal admin role for the original team.
OpenCVE Enrichment