CVE-2026-82920: Mattermost ABAC parent policy bypass via policy update endpoint
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT /api/v4/accesscontrolpolicies request with an empty imports list.. Mattermost Advisory ID: MMSA-2026-00724
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MMSA-2026-00724
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already be a channel or team administrator. The attack is performed remotely through a crafted PUT request to the access control policy update endpoint.
What is the impact of a successful exploit?
A channel or team administrator can detach a system-assigned ABAC parent policy by submitting an empty imports list. This bypasses the intended authorization boundary for that policy relationship.
Which versions are affected?
Affected releases are Mattermost 11.9.0 and earlier in the 11.9.x line, 11.8.4 and earlier in the 11.8.x line, and 11.7.7 and earlier in the 11.7.x line.