Webhook Notification Vulnerability in Mattermost Product Suite
CVE-2026-10556
5.3MEDIUM
What is CVE-2026-10556?
Mattermost versions 10.11.x up to 10.11.22 and 11.7.x through 11.9.0 have a vulnerability that fails to adequately validate null entries in Microsoft Graph webhook notifications. This flaw allows unauthenticated attackers to send a malicious {{POST}} request to the public webhook endpoint, potentially leading to a crash of the Microsoft Calendar plugin process. Consequently, this can disrupt the calendar integration functionality for all users on the affected Mattermost instance, resulting in a denial of service.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7