CVE-2026-13417
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash the Boards plugin worker and trigger a denial of service via a child block whose `fields.properties` is a non-object value. Mattermost Advisory ID: MMSA-2026-00710
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.21%
- CWE
- CWE-754
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
Weakness type
Related vulnerabilities
- CVE-2025-11925 — Incorrect Content-Type Header
- CVE-2026-79073 — Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exe
- CVE-2026-30960 — RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
- CVE-2025-0129 — Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser
- CVE-2026-79072 — Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall
- CVE-2026-24054 — Kata Containers Runtime: Host block device can be hotplugged to the VM if the container image is malformed or contains no layers
- CVE-2026-21693 — iccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cpp
- CVE-2025-24303 — Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethern