CyberRota Analysis
AI-GeneratedMattermost versions 11.9.0 and earlier in the 11.9.x, 11.8.x, and 11.7.x series are vulnerable due to insufficient enforcement of authorization boundaries on the access control policy update endpoint. This flaw allows channel or team administrators to detach a system-assigned ABAC parent policy, potentially leading to unauthorized access control modifications. Organizations using affected Mattermost versions should prioritize remediation to mitigate the risk of privilege escalation and unauthorized access.
Original NVD Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT /api/v4/access_control_policies request with an empty imports list.. Mattermost Advisory ID: MMSA-2026-00724