CVE-2026-3116: Mattermost Server

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589

Affected products

  • Mattermost Mattermost Server: from 10.11.0, before 10.11.12 (fixed in 10.11.12); from 11.2.0, before 11.2.4 (fixed in 11.2.4); from 11.3.0, before 11.3.2 (fixed in 11.3.2); from 11.4.0, before 11.4.1 (fixed in 11.4.1)

Published 2026-03-26. Last modified 2026-06-17.