VYPR
Medium severity4.2NVD Advisory· Published Aug 17, 2026· Updated Aug 18, 2026

CVE-2026-15754

CVE-2026-15754

Description

Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ABAC (attribute-based access control) policy assignments from channels outside their team via the policy unassign API after a channel has been moved to another team.. Mattermost Advisory ID: MMSA-2026-00718

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*range: >=11.7.0,<11.7.7
    • (no CPE)range: <=11.7.6, <=11.8.3

Patches

Vulnerability mechanics

References

1

News mentions

1