CVE-2026-96260: Mattermost server missing request body size limit on plugin routes allows denial of service by an authenticated user
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin endpoint.. Mattermost Advisory ID: MMSA-2026-00775
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost serverto a version that resolves this vulnerability.Fixed in 11.11.0 - Upgrade
Upgrade
Mattermost serverto a version that resolves this vulnerability.Fixed in 11.9.2 - Upgrade
Upgrade
Mattermost serverto a version that resolves this vulnerability.Fixed in 11.8.6 - Upgrade
Upgrade
Mattermost serverto a version that resolves this vulnerability.Fixed in 11.7.11 - Upgrade
Upgrade
Mattermost serverto a version that resolves this vulnerability.Fixed in 11.10.2
Event History
Frequently Asked Questions
Which deployments are affected?
Affected releases are Mattermost Server 11.9.x through 11.9.1, 11.8.x through 11.8.5, 11.7.x through 11.7.10, and 11.10.x through 11.10.1. The issue applies to plugin routes during CSRF validation.
What does an attacker need to exploit this issue?
An attacker needs to be authenticated to Mattermost and able to send a large request body to a plugin endpoint. No user interaction is required.
What is the expected impact?
A successful attack can exhaust server memory and cause a denial of service. The provided information does not indicate confidentiality or integrity impact.