CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-15814: mattermost server from 10.11.0 (inclusive), before 10.11.23 (exclusive), from 11.7.0 (inclusive), before 11.7.8…

CVE-2026-15814. CVSS 3.1 base score 6.5 (MEDIUM, Vendor/CNA). EPSS 0.00235 (percentile 0.13146), scored 2026-10-06.

Affected technology

mattermost server · from 10.11.0 (inclusive), before 10.11.23 (exclusive)
mattermost

mattermost server · from 11.7.0 (inclusive), before 11.7.8 (exclusive)
mattermost

mattermost server · from 11.8.0 (inclusive), before 11.8.5 (exclusive)
mattermost

mattermost server · from 11.9.0 (inclusive), before 11.9.1 (exclusive)
mattermost

Mattermost · 11.9.0 through 11.9.0, 11.8.0 through 11.8.4, 11.7.0 through 11.7.7, 10.11.0 through 10.11.22
Mattermost

Description’s affected range: versions 11.9.x <= 11.9.0

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

The source says mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumption and potential denial of service via uploading a specially crafted image as a profile picture, channel file attachment, team icon, or custom brand image. Vendor/CNA’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-409
CCR priority
26.1 /100 (P4)
CVSS 3.1
6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H · Vendor/CNA
EPSS
0.00235 · percentile 0.13146 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-15814.html