SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-6850

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.2 and earlier, 11.6.4 and earlier, and 10.11.19 and earlier are vulnerable due to improper validation of message attachment field values, enabling authenticated attackers to exploit this flaw. This can lead to a denial of service for all users in a channel through specially crafted payloads that cause catastrophic backtracking in the markdown parser. Organizations using affected versions should prioritize patching to mitigate potential disruptions to their communication channels.

CVE
CVE-2026-6850
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser.. Mattermost Advisory ID: MMSA-2026-00658

Related CVEs

Other vulnerabilities affecting the same vendor(s)