Junglewise Threat Intelligence

CVE-2026-82920: Mattermost authorization bypass in access control policy endpoint

CVE-2026-82920 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost, a widely-used team collaboration platform, fails to properly validate permissions on its access control policy update endpoint. A channel or team administrator can exploit this to detach system-assigned security policies, potentially bypassing organizational access controls and data protection measures that would normally prevent them from doing so.

Technical details

The vulnerability is an authorization bypass in the PUT /api/v4/access_control_policies endpoint. Mattermost fails to enforce authorization boundaries when processing requests to update access control policies, allowing a channel or team administrator to detach a system-assigned Attribute-Based Access Control (ABAC) parent policy by sending a crafted request with an empty imports list. The attack vector is network-based and requires authentication as an administrator. An attacker with these privileges can circumvent intended security policies, potentially exposing data or reducing system security posture. Patches are available in versions 11.9.1+, 11.8.5+, and 11.7.8+.

Affected products

  • Mattermost Mattermost Server 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7

Timeline

  • 2026-09-14: disclosed

References

Related threats