OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-95666

MEDIUM · CVSS 4.3 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Mattermost versions 11.9.x up to 11.9.1, 11.8.x up to 11.8.5, 11.7.x up to 11.7.10, and 11.10.x up to 11.10.1 are vulnerable due to insufficient validation of the post ID array length in the bulk reactions endpoint, allowing authenticated users to exploit this flaw to generate excessive database load. This could potentially lead to performance degradation or service outages. Organizations using affected Mattermost versions should prioritize patching to mitigate the risk of denial-of-service conditions.

CVE
CVE-2026-95666
Severity
MEDIUM
CVSS
4.3
EPSS
0.36%

Original NVD Description

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive database load via a crafted request to {{POST /api/v4/posts/ids/reactions}}.. Mattermost Advisory ID: MMSA-2026-00771

Related CVEs

Other vulnerabilities affecting the same vendor(s)