CVE-2026-10556

Summary

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted {{POST}} request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693

Affected Software

VendorProductVersion RangeStatus
MattermostMattermost11.9.0 <= 11.9.0affected
MattermostMattermost11.8.0 <= 11.8.4affected
MattermostMattermost11.7.0 <= 11.7.7affected
MattermostMattermost10.11.0 <= 10.11.22affected
MattermostMattermost11.10.0unaffected
MattermostMattermost11.9.1unaffected
MattermostMattermost11.8.5unaffected
MattermostMattermost11.7.8unaffected
MattermostMattermost10.11.23unaffected

Weaknesses

  • CWE-754: CWE-754: Improper Check for Unusual or Exceptional Conditions

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References