SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-13417

MEDIUM · CVSS 4.3

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to improper validation of `fields.properties` during block creation, allowing authenticated users with editor access to crash the Boards plugin worker. This results in a denial of service, impacting the availability of the affected boards. Organizations using these Mattermost versions should prioritize patching to mitigate potential disruptions in service.

CVE
CVE-2026-13417
Severity
MEDIUM
CVSS
4.3
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash the Boards plugin worker and trigger a denial of service via a child block whose `fields.properties` is a non-object value. Mattermost Advisory ID: MMSA-2026-00710