SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15754

MEDIUM · CVSS 4.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The vulnerability affects Mattermost versions 11.7.x up to 11.7.6 and 11.8.x up to 11.8.3, allowing authenticated team administrators to improperly unassign access control policies from channels that have been moved to different teams. This flaw could lead to unauthorized access and manipulation of channel permissions, potentially compromising sensitive information. Organizations using these Mattermost versions, particularly those with multiple teams and channels, should prioritize patching to mitigate the risk of unauthorized access.

CVE
CVE-2026-15754
Severity
MEDIUM
CVSS
4.2
EPSS
0.15%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ABAC (attribute-based access control) policy assignments from channels outside their team via the policy unassign API after a channel has been moved to another team.. Mattermost Advisory ID: MMSA-2026-00718

Related CVEs

Other vulnerabilities affecting the same vendor(s)