Channel Archiving Flaw in Mattermost Affects Multiple Versions
CVE-2026-4635
6.5MEDIUM
What is CVE-2026-4635?
A flaw in Mattermost allows authenticated users to potentially crash the server due to improper handling of persistent notifications before channel archiving. This occurs when a user creates a persistent notification message at a specific time, leading to a race condition as the server attempts to delete existing notifications and archive the channel. This can disrupt service availability in the affected Mattermost versions.
Affected Version(s)
Mattermost 11.6.0
Mattermost 11.5.0 <= 11.5.3
Mattermost 11.4.0 <= 11.4.4