CVE-2026-14298: Denial of service via resource exhaustion in Mattermost
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint.. Mattermost Advisory ID: MMSA-2026-00713
Other sources
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID: MMSA-2026-00713
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.23 - Compensating control
If immediate upgrade is not possible, restrict access to the Boards archive import endpoint to trusted/authenticated users only until Mattermost is updated to one of the fixed versions (11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14298?
CVE-2026-14298 has a medium severity rating of 6.5.
How do I fix CVE-2026-14298?
To fix CVE-2026-14298, upgrade Mattermost Boards to versions above 11.9.0, 11.8.4, 11.7.7, or 10.11.22.
What type of attack does CVE-2026-14298 enable?
CVE-2026-14298 allows authenticated users to perform resource exhaustion attacks via zip bombs or file size limit bypass.
Which versions of Mattermost are affected by CVE-2026-14298?
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, and 10.11.x <= 10.11.22 are affected by CVE-2026-14298.
What is the impact of CVE-2026-14298?
CVE-2026-14298 can lead to memory exhaustion or unbounded disk consumption due to insufficient content size limitation.