CSRF Vulnerability in Mattermost Plugin for Authenticated Users
CVE-2026-96260
6.5MEDIUM
What is CVE-2026-96260?
Mattermost versions up to 11.10.1 have a vulnerability that fails to enforce a limit on the request body size during CSRF validation for plugin requests. This oversight allows authenticated users to exploit the vulnerability by sending oversized requests to plugin endpoints, potentially exhausting server memory and leading to service disruption.
Affected Version(s)
Mattermost 11.9.0 <= 11.9.1
Mattermost 11.8.0 <= 11.8.5
Mattermost 11.7.0 <= 11.7.10