Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted {{POST}} request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 11:17
Updated : 2026-09-14 12:17
NVD link : CVE-2026-10556
Mitre link : CVE-2026-10556
CVE.ORG link : CVE-2026-10556
JSON object : View
Products Affected
No product.
CWE
CWE-754
Improper Check for Unusual or Exceptional Conditions
