Impact
Mattermost servers running affected versions fail to validate null entries in Microsoft Graph webhook notification payloads. An unauthenticated attacker can craft a POST request to the public webhook endpoint to trigger a crash of the Microsoft Calendar plugin process. The resultant loss of calendar integration for all users constitutes a denial of service, and the weakness is exemplified by CWE‑754, improper input validation.
Affected Systems
The vulnerability impacts Mattermost servers, particularly versions 11.9.x up to 11.9.0, 11.8.x up to 11.8.4, 11.7.x up to 11.7.7, and 10.11.x up to 10.11.22. These releases are deprecated in favor of patched versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or later.
Risk and Exploitability
With a CVSS score of 5.3 and no EPSS available, the vulnerability represents a moderate risk. It is not listed in CISA’s KEV catalog, but the attack vector requires no special privileges—any user capable of sending a POST request to the exposed webhook can exploit it. The absence of authentication makes exploitation straightforward, and the impact affects all users' calendar integration.
OpenCVE Enrichment