CVE-2026-2325: Improper Input Validation in MS Teams Meetings API Handler
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST request to {{/api/v1/meetings}}.. Mattermost Advisory ID: MMSA-2026-00608
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2325?
CVE-2026-2325 is classified as a medium severity vulnerability due to its potential for resource exhaustion and denial of service attacks.
How do I fix CVE-2026-2325?
To fix CVE-2026-2325, upgrade Mattermost to version 11.5.2, 10.11.14, or 11.4.4 or later, which contain the necessary patches.
Who is affected by CVE-2026-2325?
CVE-2026-2325 affects Mattermost versions 11.5.x up to 11.5.1, 10.11.x up to 10.11.13, and 11.4.x up to 11.4.3.
What is the nature of the vulnerability in CVE-2026-2325?
CVE-2026-2325 involves improper input validation that allows for unbounded request body sizes on the start meeting API endpoint.
Can CVE-2026-2325 be exploited remotely?
Yes, CVE-2026-2325 can be exploited by an authenticated attacker remotely, leading to possible denial of service.