CVE-2023-49809: Mattermost Server

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoint and make it crash. After a few repetitions, the plugin is disabled. 

Affected products

  • Mattermost Mattermost Server: up to and including 8.1.5; from 9.0.0, up to and including 9.1.0

Published 2023-12-12. Last modified 2026-06-17.