Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA-2026-00701
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 14:17
Updated : 2026-09-14 20:17
NVD link : CVE-2026-86348
Mitre link : CVE-2026-86348
CVE.ORG link : CVE-2026-86348
JSON object : View
Products Affected
No product.
CWE
CWE-704
Incorrect Type Conversion or Cast
