SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82920

MEDIUM · CVSS 5.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Mattermost versions 11.9.0 and earlier in the 11.9.x, 11.8.x, and 11.7.x series are vulnerable due to insufficient enforcement of authorization boundaries on the access control policy update endpoint. This flaw allows channel or team administrators to detach a system-assigned ABAC parent policy, potentially leading to unauthorized access control modifications. Organizations using affected Mattermost versions should prioritize remediation to mitigate the risk of privilege escalation and unauthorized access.

CVE
CVE-2026-82920
Severity
MEDIUM
CVSS
5.5
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT /api/v4/access_control_policies request with an empty imports list.. Mattermost Advisory ID: MMSA-2026-00724