Excessive Database Load Vulnerability in Mattermost by Mattermost
CVE-2026-95666

4.3MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
22 September 2026

What is CVE-2026-95666?

The Mattermost platform contains a vulnerability that affects several versions, allowing authenticated users to exploit the bulk reactions endpoint by submitting excessively long post ID arrays. This can lead to a severe increase in database load, potentially disrupting service functionality. Users of Mattermost should be aware of this risk and consider applying necessary patches to mitigate the issue.

Affected Version(s)

Mattermost 11.9.0 <= 11.9.1

Mattermost 11.8.0 <= 11.8.5

Mattermost 11.7.0 <= 11.7.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

idr
.