SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-10600

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Mattermost versions 11.8.0 and earlier, 11.7.3 and earlier, 11.6.5 and earlier, and 10.11.20 and earlier are vulnerable to a resource exhaustion attack due to inadequate bounding of server-side document content extraction processes. An authenticated user with file-upload permissions can exploit this vulnerability by repeatedly uploading small files, leading to service degradation for all users by saturating the shared extraction worker pool. Organizations using these affected versions should prioritize remediation to prevent potential disruptions in service availability.

CVE
CVE-2026-10600
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%

Original NVD Description

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694

Related CVEs

Other vulnerabilities affecting the same vendor(s)