Impact
Mattermost versions 11.9.x through 11.7.x allow the ABAC parent policy to be detached by an attacker who can perform administrative actions on a channel or team. By sending a crafted PUT request to /api/v4/access_control_policies with an empty imports list, the system fails to enforce. The missing enforcement is a classic authorization boundary weakness (CWE‑863) and can be leveraged to reduce the scope of an organization’s access control model, potentially allowing an attacker to elevate privileges or bypass restrictions set by higher‑level policies.
Affected Systems
The affected product is Mattermost. Vulnerable releases include Mattermost 11.9.x versions up to and including 11.9.0, Mattermost 11.8.x versions up to and including 11.8.4, and Mattermost 11.7.x versions up to and including 11.7.7.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog. Attackers must already have administrative permissions on a channel or team to exploit the flaw, therefore the attack vector is limited to users with elevated rights. If such an attacker can manipulate the ABAC policy, they can bypass security controls that rely on the parent policy, leading to broader access rights or data exposure within the Mattermost instance.
OpenCVE Enrichment