SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-86349

MEDIUM · CVSS 4.3

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to an insufficient limit on nesting depth in the server-side Markdown parser, which can be exploited by authenticated attackers to create crafted posts that lead to CPU resource exhaustion and denial of service. Organizations using affected Mattermost versions should prioritize this vulnerability to prevent potential service disruptions caused by maliciously crafted content. Immediate action is recommended for teams managing chat or collaboration platforms that rely on Mattermost for communication.

CVE
CVE-2026-86349
Severity
MEDIUM
CVSS
4.3
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU resource exhaustion) via a crafted post containing deeply nested blockquotes or list items.. Mattermost Advisory ID: MMSA-2026-00707