What is CVE-2026-15754?
This vulnerability in Mattermost's access control policy unassign endpoint fails to re-validate channel ownership, allowing an authenticated team administrator to remove ABAC policies from channels outside their team. Mattermost versions 11.7.x <= 11.7.6 and 11.8.x <= 11.8.3 are affected, users should update to the latest patched version immediately.
Azərbaycanca: Bu boşluq Mattermost-un təyin olunmuş giriş nəzarəti siyasətinin ləğvi (unassign) endpointində aşkarlanıb ki, autentifikasiya olunmuş komanda administratoruna öz komandasına aid olmayan kanallardan ABAC siyasətini silməyə imkan verir. Mattermost 11.7.x <= 11.7.6 və 11.8.x <= 11.8.3 versiyaları təsirə məruz qalır, istifadəçilər dərhal ən son təhlükəsizlik yeniləməsinə keçməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Mattermost
FAQ1
Which Mattermost versions are affected by CVE-2026-15754?
This vulnerability affects Mattermost versions 11.7.x <= 11.7.6 and 11.8.x <= 11.8.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.