CVE-2026-27659 | Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0/11.4.x Access Control Policy activate cross-site request forgery
A vulnerability identified as problematic has been detected in Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0/11.4.x. This impacts an unknown function of the file /api/v4/access_control_policies/{policy_id}/activate of the component Access Control Policy. Performing a manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2026-27659. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.