CVE-2026-86348: MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process
Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA-2026-00701
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.23 - Compensating control
Mattermost Advisory ID: MMSA-2026-00701 notes that versions <=11.9 and listed patch levels fail to recover from handler panics; if immediate upgrade is not possible, mitigate by limiting authenticated users’ ability to send post-action requests to the Calendar plugin endpoints (e.g., via network/ACL restrictions to trusted clients).
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user can trigger the crash by sending a post-action request containing an unexpected field type. No user interaction is required.
What is the likely impact of successful exploitation?
Successful exploitation can crash the MS Calendar plugin process, causing an availability impact to that plugin. The provided severity vector indicates no confidentiality or integrity impact.
Which Mattermost releases are listed as affected?
The advisory lists Mattermost versions <=11.9, 11.0.9, 11.4.8, 11.7.7, and 10.22.11.0 as affected.