Vulnerability Details CVE-2026-96260
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin endpoint.. Mattermost Advisory ID: MMSA-2026-00775
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 33.2%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-96260
-
cpe:2.3:a:mattermost:mattermost_server:11.10.0
-
cpe:2.3:a:mattermost:mattermost_server:11.10.1
-
cpe:2.3:a:mattermost:mattermost_server:11.8.0
-
cpe:2.3:a:mattermost:mattermost_server:11.8.1
-
cpe:2.3:a:mattermost:mattermost_server:11.8.2
-
cpe:2.3:a:mattermost:mattermost_server:11.8.3
-
cpe:2.3:a:mattermost:mattermost_server:11.8.4
-
cpe:2.3:a:mattermost:mattermost_server:11.8.5