SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15814

MEDIUM · CVSS 6.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Mattermost versions 11.9.0 and earlier, 11.8.4 and earlier, 11.7.7 and earlier, and 10.11.22 and earlier are vulnerable to excessive memory consumption due to improper handling of uploaded image files, allowing authenticated users to potentially trigger a denial of service. This vulnerability can be exploited by uploading specially crafted images as profile pictures, file attachments, or team icons. Organizations using these versions should prioritize patching to mitigate the risk of service disruption.

CVE
CVE-2026-15814
Severity
MEDIUM
CVSS
6.5
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumption and potential denial of service via uploading a specially crafted image as a profile picture, channel file attachment, team icon, or custom brand image. Mattermost Advisory ID: MMSA-2026-00719