CVE-2026-10556

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted {{POST}} request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693
References
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 11:17

Updated : 2026-09-14 12:17


NVD link : CVE-2026-10556

Mitre link : CVE-2026-10556

CVE.ORG link : CVE-2026-10556


JSON object : View

Products Affected

No product.

CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions