Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash the Boards plugin worker and trigger a denial of service via a child block whose `fields.properties` is a non-object value. Mattermost Advisory ID: MMSA-2026-00710
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Mattermost Boards plugin fails to validate the type of fields.properties when a block is created. If an authenticated editor constructs a child block whose fields.properties is a non‑object value, the plugin worker crashes, raising a denial of service condition on the affected board. This flaw is a classic unvalidated input problem (CWE‑754) and allows an insider with editor rights to disrupt service without requiring any elevated privileges.

Affected Systems

Mattermost servers running affected releases are impacted, including 11.9.x releases up to and including 11.9.0, 11.8.4, 11.7.x releases up to and including 11.7.7, and 10.11.x releases up to and including 10.11.22. All other Mattermost versions receive the fix and are not vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of active exploitation. Nevertheless, the flaw is exploitable by any authenticated user with editor access, making it a practical risk for organizations that rely heavily on Mattermost Boards.

Generated by OpenCVE AI on September 15, 2026 at 14:27 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to at least 11.10.0, 11.9.1, 11.8.5, 11.7.8, or 10.11.23 or newer, which includes the vendor’s fix for this denial of service.
  • If an immediate update is not feasible, temporarily remove or revoke editor permissions for the affected boards, or disable the Boards plugin until a patch can be applied.
  • Continuously monitor server logs for unexpected worker crashes or sudden service interruptions that could indicate an attempted exploitation attempt.

Generated by OpenCVE AI on September 15, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash the Boards plugin worker and trigger a denial of service via a child block whose `fields.properties` is a non-object value. Mattermost Advisory ID: MMSA-2026-00710
Title Boards plugin denial of service via unvalidated block fields.properties
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T11:19:44.392Z

Reserved: 2026-06-26T11:40:33.086Z

Link: CVE-2026-13417

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:24.681Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:03.180

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-13417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions