Description
Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA-2026-00701
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Mattermost versions up to 11.9, 11.0.9, 11.4.8, 11.7.7, and 10.22.11.0 do not recover from handler panics caused by malformed post‑action requests, allowing an authenticated user to crash the MS Calendar plugin process.

Affected Systems

The affected product is Mattermost, specifically the MS Calendar plugin. Vulnerable versions include any release 10.22.11.0 or earlier, 11.0.9 or earlier, 11.4.8 or earlier, 11.7.7 or earlier, and 11.9 or earlier.

Risk and Exploitability

The CVSS score is 4.3 and the EPSS score is not available. The vulnerability is not listed in CISA KEV. Attack requires an authenticated user who can send a post‑action request with an unexpected field type to trigger the non‑recoverable panic and cause a denial‑of‑service of the plugin. No remote code execution or data exfiltration is possible.

Generated by OpenCVE AI on September 15, 2026 at 14:19 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to version 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or newer.
  • If the MS Calendar plugin is not essential, disable or uninstall it to eliminate the vulnerability.
  • Configure the plugin or system to validate post‑action request fields and restrict permissions for authenticated users, and monitor logs for plugin panics to detect repeated exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA-2026-00701
Title MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process
Weaknesses CWE-704
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T19:23:01.298Z

Reserved: 2026-09-07T09:35:28.446Z

Link: CVE-2026-86348

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:28.648Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T14:17:15.570

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-86348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-704

    Incorrect Type Conversion or Cast