Aller au contenu

Fiche vulnérabilité

CVE-2026-4635 : faille moyenne mattermost mattermost server (CVSS 5.3)

Description

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persistent notification message between the server deleting existing persistent notifications and archiving the channel.. Mattermost Advisory ID: MMSA-2026-00637

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
22 mai 2026
Dernière mise à jour
23 juil. 2026

Produits concernés

  • mattermost mattermost server

Références

Rechercher une autre vulnérabilité dans la base CVE