CVE-2026-14298: Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in Mattermost
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint.. Mattermost Advisory ID: MMSA-2026-00713
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.23
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14298?
CVE-2026-14298 has a medium severity rating of 6.5.
How do I fix CVE-2026-14298?
To fix CVE-2026-14298, upgrade Mattermost Boards to versions above 11.9.0, 11.8.4, 11.7.7, or 10.11.22.
What type of attack does CVE-2026-14298 enable?
CVE-2026-14298 allows authenticated users to perform resource exhaustion attacks via zip bombs or file size limit bypass.
Which versions of Mattermost are affected by CVE-2026-14298?
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, and 10.11.x <= 10.11.22 are affected by CVE-2026-14298.
What is the impact of CVE-2026-14298?
CVE-2026-14298 can lead to memory exhaustion or unbounded disk consumption due to insufficient content size limitation.