VYPR
Medium severity6.5NVD Advisory· Published Aug 13, 2026· Updated Sep 14, 2026

CVE-2026-14298

CVE-2026-14298

Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint.. Mattermost Advisory ID: MMSA-2026-00713

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*range: >=10.11.0,<10.11.23
    • (no CPE)range: <=11.9.0, <=11.8.4, <=11.7.7, <=10.11.22
  • Range: <=11.9.0, <=11.8.4, <=11.7.7, <=10.11.22

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.