CVE-2026-10556
Received Received - Intake

Microsoft Graph Webhook Null Entry Validation Bypass in Mattermost

Vulnerability report for CVE-2026-10556, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted {{POST}} request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.9.0 (inc)
mattermost mattermost to 11.8.4 (inc)
mattermost mattermost to 11.7.7 (inc)
mattermost mattermost to 10.11.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mattermost versions between 11.9.0 and older, 11.8.4 and older, 11.7.7 and older, and 10.11.22 and older fail to validate null entries in Microsoft Graph webhook notifications. This allows an unauthenticated attacker to send a crafted POST request to crash the Microsoft Calendar plugin process, disrupting calendar integration for all users on the instance.

Detection Guidance

This vulnerability can be detected by checking Mattermost server logs for unusual POST requests to the Microsoft Calendar plugin webhook endpoint. Look for entries with null payloads or malformed requests targeting the public webhook URL.

Impact Analysis

This vulnerability can cause denial of service by crashing the Microsoft Calendar plugin, preventing all users from accessing calendar integration features on the affected Mattermost instance.

Compliance Impact

The vulnerability allows denial of service to calendar integration via crafted requests, which could disrupt user access to critical services. This may impact compliance with GDPR (availability of services) or HIPAA (disruption of integrated systems handling PHI) if calendar data is used for scheduling or notifications.

Mitigation Strategies

Upgrade Mattermost to a patched version (11.9.1 or later, 11.8.5 or later, 11.7.8 or later, or 10.11.23 or later). If immediate upgrade is not possible, disable the Microsoft Calendar plugin until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10556. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart