Vulnerability Description
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost Server | >= 10.11.0, < 10.11.21 |
Related Weaknesses (CWE)
References
- https://mattermost.com/security-updatesVendor Advisory
FAQ
What is CVE-2026-10600?
CVE-2026-10600 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an...
How severe is CVE-2026-10600?
CVE-2026-10600 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-10600?
Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost Server.