CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-12882: mattermost server from 10.11.0 (inclusive), before 10.11.23 (exclusive), from 11.7.0 (inclusive), before 11.7.8…

CVE-2026-12882. CVSS 3.1 base score 4.3 (MEDIUM, Vendor/CNA). EPSS 0.00212 (percentile 0.10509), scored 2026-10-06.

Affected technology

mattermost server · from 10.11.0 (inclusive), before 10.11.23 (exclusive)
mattermost

mattermost server · from 11.7.0 (inclusive), before 11.7.8 (exclusive)
mattermost

mattermost server · from 11.8.0 (inclusive), before 11.8.5 (exclusive)
mattermost

mattermost server · from 11.9.0 (inclusive), before 11.9.1 (exclusive)
mattermost

Mattermost · 11.9.0 through 11.9.0, 11.8.0 through 11.8.4, 11.7.0 through 11.7.7, 10.11.0 through 10.11.22
Mattermost

Description’s affected range: versions 11.9.x <= 11.9.0

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An authenticated user with permission to create posts can cause excessive server CPU consumption and degrade availability for other users via specially crafted post or message attachment content. Vendor/CNA’s CVSS 3.1 assessment (base score 4.3/10) rates confidentiality and integrity impact as none; availability impact as low.

Published

CWE
CWE-407
CCR priority
17.3 /100 (P5)
CVSS 3.1
4.3 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L · Vendor/CNA
EPSS
0.00212 · percentile 0.10509 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-12882.html