SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-10556

MEDIUM · CVSS 5.3

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to improper validation of null entries in Microsoft Graph webhook notification payloads, allowing unauthenticated attackers to crash the Microsoft Calendar plugin. This results in a denial of service for calendar integration, impacting all users on the affected instance. Organizations using these Mattermost versions should prioritize remediation to maintain service availability and prevent disruptions.

CVE
CVE-2026-10556
Severity
MEDIUM
CVSS
5.3
EPSS
N/A
Microsoft

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted {{POST}} request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693