CVE-2026-13417: Boards plugin denial of service via unvalidated block fields.properties
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of fields.properties on block creation which allows an authenticated user with editor access to a board to crash the Boards plugin worker and trigger a denial of service via a child block whose fields.properties is a non-object value. Mattermost Advisory ID: MMSA-2026-00710
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Boards pluginto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
Mattermost Boards pluginto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
Mattermost Boards pluginto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
Mattermost Boards pluginto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
Mattermost Boards pluginto a version that resolves this vulnerability.Fixed in 10.11.23
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who has editor access to a board can exploit it. The issue is reachable over the network and does not require user interaction.
What condition triggers the denial of service?
The attacker must create a child block with fields.properties set to a non-object value. This can crash the Boards plugin worker and cause a denial of service.
Which releases are affected?
Affected releases are Mattermost 11.9.0 and earlier 11.9.x releases, 11.8.4 and earlier 11.8.x releases, 11.7.7 and earlier 11.7.x releases, and 10.11.22 and earlier 10.11.x releases.