CVE-2026-13417
Received Received - Intake

Denial of Service in Mattermost Boards Plugin via Invalid Block Properties

Vulnerability report for CVE-2026-13417, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash the Boards plugin worker and trigger a denial of service via a child block whose `fields.properties` is a non-object value. Mattermost Advisory ID: MMSA-2026-00710

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.9.0 (inc)
mattermost mattermost to 11.8.4 (inc)
mattermost mattermost to 11.7.7 (inc)
mattermost mattermost to 10.11.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Mattermost versions 11.9.0 and below, 11.8.4 and below, 11.7.7 and below, and 10.11.22 and below. It allows an authenticated user with editor access to a board to crash the Boards plugin worker and cause a denial of service by creating a child block with a non-object value in the fields.properties property.

Detection Guidance

This vulnerability involves improper validation of fields.properties in Mattermost Boards plugin. To detect it, check Mattermost server logs for crashes in the Boards plugin worker. Look for errors related to invalid type handling in block creation. Ensure your Mattermost instance is running versions 11.9.1, 11.8.5, 11.7.8, or later.

Impact Analysis

If exploited, this vulnerability could cause the Boards plugin to crash repeatedly, leading to service disruption and preventing users from accessing board functionality. It requires an attacker to have editor access, limiting the scope of potential impact.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is a denial-of-service issue in the Mattermost Boards plugin. However, service disruptions could impact availability requirements under these regulations if they lead to prolonged downtime.

Mitigation Strategies

Update Mattermost to a version that is not affected by this vulnerability. Specifically, upgrade to versions beyond 11.9.0, 11.8.4, 11.7.7, or 10.11.22 depending on your current installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13417. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart