Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID: MMSA-2026-00713
Published: 2026-08-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost versions 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, allowing an authenticated user to cause a denial of service.

Affected Systems

The issue affects Mattermost, specifically versions 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22.

Risk and Exploitability

This vulnerability has a CVSS score of 6.5, indicating a moderate level of severity. The EPSS score is not available, so the exploit probability is currently unknown, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated to trigger the vulnerability, but the lack of proper resource limits makes it straightforward to abuse the upload mechanism to exhaust system resources. No public exploit has yet been observed, but the risk is significant for installations that allow ordinary users to import boards.

Generated by OpenCVE AI on August 13, 2026 at 10:30 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to version 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or any later release that incorporates the fix.
  • Limit the Boards import endpoint to administrators by configuring role-based access controls.
  • Implement application or server resource limits (e.g., memory and disk quotas) to mitigate the impact of oversized uploads.

Generated by OpenCVE AI on August 13, 2026 at 10:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Thu, 13 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint.. Mattermost Advisory ID: MMSA-2026-00713 Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID: MMSA-2026-00713
Title Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in Mattermost Denial of service via resource exhaustion in Mattermost

Thu, 13 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint.. Mattermost Advisory ID: MMSA-2026-00713
Title Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in Mattermost
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattermost Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-13T14:16:56.354Z

Reserved: 2026-07-01T10:07:28.258Z

Link: CVE-2026-14298

cve-icon Vulnrichment

Updated: 2026-08-13T14:16:51.361Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-13T09:17:11.860

Modified: 2026-08-18T16:20:52.257

Link: CVE-2026-14298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:45:03Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)