Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT /api/v4/access_control_policies request with an empty imports list.. Mattermost Advisory ID: MMSA-2026-00724
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass
Action: Apply patch
AI Analysis

Impact

Mattermost versions 11.9.x through 11.7.x allow the ABAC parent policy to be detached by an attacker who can perform administrative actions on a channel or team. By sending a crafted PUT request to /api/v4/access_control_policies with an empty imports list, the system fails to enforce. The missing enforcement is a classic authorization boundary weakness (CWE‑863) and can be leveraged to reduce the scope of an organization’s access control model, potentially allowing an attacker to elevate privileges or bypass restrictions set by higher‑level policies.

Affected Systems

The affected product is Mattermost. Vulnerable releases include Mattermost 11.9.x versions up to and including 11.9.0, Mattermost 11.8.x versions up to and including 11.8.4, and Mattermost 11.7.x versions up to and including 11.7.7.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog. Attackers must already have administrative permissions on a channel or team to exploit the flaw, therefore the attack vector is limited to users with elevated rights. If such an attacker can manipulate the ABAC policy, they can bypass security controls that rely on the parent policy, leading to broader access rights or data exposure within the Mattermost instance.

Generated by OpenCVE AI on September 15, 2026 at 13:46 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to any version of 11.10.0, 11.9.1, 11.8.5, 11.7.8 or higher that includes the ABAC parent policy enforcement fix
  • Confirm that any existing ABAC parent policies cannot be overridden by empty imports and that the policy list is non‑empty
  • Restrict the /api/v4/access_control_policies API to only allow users with system‑admin or relevant role privileges to modify policies

Generated by OpenCVE AI on September 15, 2026 at 13:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT /api/v4/access_control_policies request with an empty imports list.. Mattermost Advisory ID: MMSA-2026-00724
Title Mattermost ABAC parent policy bypass via policy update endpoint
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T19:23:01.097Z

Reserved: 2026-08-31T11:19:09.113Z

Link: CVE-2026-82920

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:26.488Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T14:17:13.010

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-82920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:00:11Z

Weaknesses