Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spawn more goroutines than intended and block the indexing of other files via uploading heavy files constantly to the server.. Mattermost Advisory ID: MMSA-2026-00696
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Patch
AI Analysis

Impact

Mattermost versions up to 11.9.0, 11.8.4, 11.7.7, and 10.11.22 improperly enforce limits on concurrent file processing and handling of failed files. A user with permission to upload files can create more worker goroutines than intended, causing the extraction pool to fill and preventing other files from being indexed. The primary effect is a denial of service that blocks indexing for legitimate content, impacting availability for all users.

Affected Systems

The affected product is Mattermost. The vulnerable releases are 10.11.x versions up to and including 10.11.22, 11.7.x up to and including 11.7.7, 11.8.x up to and including 11.8.4, and 11.9.x up to and including 11.9.0. All subsequent releases above 10.11.23, 11.7.8, 11.8.5, 11.9.1, and 11.10.0 contain the fix.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated members with file upload rights; typical exploitation involves submitting large or repeated files to exhaust the extraction pool. While it does not lead to code execution, the denial of service could disrupt collaboration services.

Generated by OpenCVE AI on September 15, 2026 at 14:39 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to at least 11.10.0, 11.9.1, 11.8.5, 11.7.8, or 10.11.23 and higher.
  • Restrict file upload permissions to trusted users to limit the potential for resource exhaustion.
  • Monitor server resource utilization and indexing queue length, and configure alerts when thresholds are approached.

Generated by OpenCVE AI on September 15, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spawn more goroutines than intended and block the indexing of other files via uploading heavy files constantly to the server.. Mattermost Advisory ID: MMSA-2026-00696
Title Fix authenticated members disabling file content indexing server-wide via extraction pool exhaustion
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T19:36:34.391Z

Reserved: 2026-06-11T14:54:55.079Z

Link: CVE-2026-11993

cve-icon Vulnrichment

Updated: 2026-09-14T19:36:29.817Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:02.800

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-11993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:45:11Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling