Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT /api/v4/access_control_policies request with an empty imports list.. Mattermost Advisory ID: MMSA-2026-00724 | |
| Title | Mattermost ABAC parent policy bypass via policy update endpoint | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-09-14T19:23:01.097Z
Reserved: 2026-08-31T11:19:09.113Z
Link: CVE-2026-82920
Updated: 2026-09-14T19:15:26.488Z
Status : Received
Published: 2026-09-14T14:17:13.010
Modified: 2026-09-14T20:16:57.467
Link: CVE-2026-82920
No data.
OpenCVE Enrichment
Updated: 2026-09-14T20:00:08Z
-
CWE-863
Incorrect Authorization