CVE-2026-10080
Received Received - Intake

Denial of Service in Mattermost via WebSocket Command

Vulnerability report for CVE-2026-10080, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards users via a custom_focalboard_SUBSCRIBE_TEAM message with a non-string teamId.. Mattermost Advisory ID: MMSA-2026-00687

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.7.6 (inc)
mattermost mattermost to 10.11.21 (inc)
mattermost mattermost to 11.8.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-704 The product does not correctly convert an object, resource, or structure from one type to a different type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Mattermost versions between 11.7.0 and 11.7.6, 10.11.0 and 10.11.21, and 11.8.0 and 11.8.3. It allows an authenticated user to send a malformed WebSocket message with a non-string teamId field to crash the plugin process. This denial-of-service condition prevents all Boards users from accessing the service.

Detection Guidance

Detecting this vulnerability requires checking Mattermost server logs for malformed WebSocket SUBSCRIBE_TEAM messages with non-string teamId fields. Monitor for crashes in the Boards plugin process or service disruptions to users.

Impact Analysis

If you use a vulnerable Mattermost version, an attacker with valid credentials could disrupt service for all Boards users by sending a specially crafted WebSocket message. This would make the Boards feature unavailable until the server is restarted or the issue is resolved.

Compliance Impact

The vulnerability causes a denial of service for Boards users by crashing the plugin process, which could disrupt access to critical data. This may impact compliance with GDPR or HIPAA if it leads to prolonged unavailability of personal or health data, potentially violating availability requirements.

Mitigation Strategies

Upgrade Mattermost to a patched version (11.7.7+, 10.11.22+, or 11.8.4+) immediately. If upgrading is not possible, restrict authenticated user access to Boards features or disable the Boards plugin until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10080. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart