CVE-2026-15754: Missing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removal
Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ABAC (attribute-based access control) policy assignments from channels outside their team via the policy unassign API after a channel has been moved to another team.. Mattermost Advisory ID: MMSA-2026-00718
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.7 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.4 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15754?
CVE-2026-15754 has a medium severity score of 4.2.
How do I fix CVE-2026-15754?
To fix CVE-2026-15754, update Mattermost to version 11.7.7 or 11.8.4 or later.
What software is affected by CVE-2026-15754?
CVE-2026-15754 affects Mattermost versions 11.7.x up to 11.7.6 and 11.8.x up to 11.8.3.
What type of vulnerability is CVE-2026-15754?
CVE-2026-15754 is a cross-team policy removal vulnerability in the ABAC access control policy.
Can an unauthenticated user exploit CVE-2026-15754?
No, CVE-2026-15754 can only be exploited by an authenticated team administrator.