Server-Side Resource Exhaustion in Mattermost Affects Document Uploads
CVE-2026-10600

4.3MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
27 July 2026

What is CVE-2026-10600?

In Mattermost, versions 11.8.x up to 11.8.0, 11.7.x up to 11.7.3, 11.6.x up to 11.6.5, and 10.11.x up to 10.11.20, a vulnerability exists in the handling of document uploads. Authenticated users with file-upload permissions can exploit this flaw by repeatedly uploading small documents, which are inexpensive to upload but costly to process. This behavior can exhaust the server’s resources by saturating the shared extraction worker pool, leading to performance degradation for all users. For more information, refer to the advisory MMSA-2026-00694.

Affected Version(s)

Mattermost 11.8.0

Mattermost 11.7.0 <= 11.7.3

Mattermost 11.6.0 <= 11.6.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

abderrahimelkahlaoui
.