Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted {{POST}} request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service due to Microsoft Calendar plugin crash
Action: Patch
AI Analysis

Impact

Mattermost servers running affected versions fail to validate null entries in Microsoft Graph webhook notification payloads. An unauthenticated attacker can craft a POST request to the public webhook endpoint to trigger a crash of the Microsoft Calendar plugin process. The resultant loss of calendar integration for all users constitutes a denial of service, and the weakness is exemplified by CWE‑754, improper input validation.

Affected Systems

The vulnerability impacts Mattermost servers, particularly versions 11.9.x up to 11.9.0, 11.8.x up to 11.8.4, 11.7.x up to 11.7.7, and 10.11.x up to 10.11.22. These releases are deprecated in favor of patched versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or later.

Risk and Exploitability

With a CVSS score of 5.3 and no EPSS available, the vulnerability represents a moderate risk. It is not listed in CISA’s KEV catalog, but the attack vector requires no special privileges—any user capable of sending a POST request to the exposed webhook can exploit it. The absence of authentication makes exploitation straightforward, and the impact affects all users' calendar integration.

Generated by OpenCVE AI on September 15, 2026 at 14:26 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Apply the official upgrade to a patched Mattermost version such as 11.10.0 or later
  • Ensure the Microsoft Calendar plugin runs on the same updated server version
  • Until the patch is applied, restrict or block access to the public webhook endpoint using firewall or authentication rules

Generated by OpenCVE AI on September 15, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted {{POST}} request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693
Title Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T11:19:44.241Z

Reserved: 2026-06-01T14:36:14.113Z

Link: CVE-2026-10556

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:22.629Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:02.590

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-10556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions