CVE-2026-14298: Denial of service via resource exhaustion in Mattermost
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID: MMSA-2026-00713
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.10.0Patch MMSA-2026-00713 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.1Patch MMSA-2026-00713 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.5Patch MMSA-2026-00713 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.8Patch MMSA-2026-00713 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.23Patch MMSA-2026-00713
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14298?
CVE-2026-14298 has a medium severity rating of 6.5.
How do I fix CVE-2026-14298?
To fix CVE-2026-14298, upgrade Mattermost Boards to versions above 11.9.0, 11.8.4, 11.7.7, or 10.11.22.
What type of attack does CVE-2026-14298 enable?
CVE-2026-14298 allows authenticated users to perform resource exhaustion attacks via zip bombs or file size limit bypass.
Which versions of Mattermost are affected by CVE-2026-14298?
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, and 10.11.x <= 10.11.22 are affected by CVE-2026-14298.
What is the impact of CVE-2026-14298?
CVE-2026-14298 can lead to memory exhaustion or unbounded disk consumption due to insufficient content size limitation.