CVE-2026-10556
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted {{POST}} request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.25%
- CWE
- CWE-754
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
Weakness type
Related vulnerabilities
- CVE-2025-11925 — Incorrect Content-Type Header
- CVE-2026-79073 — Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exe
- CVE-2026-30960 — RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
- CVE-2025-0129 — Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser
- CVE-2026-79072 — Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall
- CVE-2026-24054 — Kata Containers Runtime: Host block device can be hotplugged to the VM if the container image is malformed or contains no layers
- CVE-2026-21693 — iccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cpp
- CVE-2025-24303 — Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethern