CyberRota Analysis
AI-GeneratedMattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 are vulnerable due to inadequate validation of WebSocket command field types, allowing authenticated users to send a malformed message that can crash the plugin process. This results in a denial of service for all users on the Boards platform. Organizations using these Mattermost versions should prioritize patching to mitigate potential service disruptions.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards users via a custom_focalboard_SUBSCRIBE_TEAM message with a non-string teamId.. Mattermost Advisory ID: MMSA-2026-00687
Related CVEs
Other vulnerabilities affecting the same vendor(s)