CVE-2026-10080CWE-704

CVE-2026-10080

Medium · published August 18, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
21.9
In the wild
Unconfirmed
What it is

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards users via a custom_focalboard_SUBSCRIBE_TEAM message with a non-string teamId.. Mattermost Advisory ID: MMSA-2026-00687

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00296 · 21.9th percentile
Weakness
CWE-704 · Incorrect Type Conversion or Cast
Published
2026-08-18T02:16Z
Affected products (3)
ProductVersionsFixed in
mattermost/mattermost_server≥ 10.11.0, < 10.11.2210.11.22
mattermost/mattermost_server≥ 11.7.0, < 11.7.711.7.7
mattermost/mattermost_server≥ 11.8.0, < 11.8.411.8.4
References (1)
EPSS history
Timeline
  • 17 AUG 22:04Z
    Boards plugin panics on WebSocket command with non-string field types
    cvelistv5