CVE-2026-6850
published 2026-07-13CVE-2026-6850: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.24%
15.2th percentile
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser.. Mattermost Advisory ID: MMSA-2026-00658
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | 10.11.0 – 10.11.19 | — |
| mattermost | mattermost | 11.6.0 – 11.6.4 | — |
| mattermost | mattermost | 11.7.0 – 11.7.2 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.20 | 10.11.20 |
| mattermost | mattermost_server | >= 11.6.0 < 11.6.5 | 11.6.5 |
| mattermost | mattermost_server | >= 11.7.0 < 11.7.3 | 11.7.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mattermost up to 10.11.19/11.6.4/11.7.2 Client-Side Markdown Parser attachment cross site scripting (Nessus ID 327418)
vuldb·2026-07-18·CVSS 6.5
CVE-2026-6850 [MEDIUM] Mattermost up to 10.11.19/11.6.4/11.7.2 Client-Side Markdown Parser attachment cross site scripting (Nessus ID 327418)
A vulnerability marked as problematic has been reported in Mattermost up to 10.11.19/11.6.4/11.7.2. Affected by this vulnerability is an unknown functionality of the component Client-Side Markdown Parser. The manipulation of the argument attachment leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-6850. The attack is possible to be carried out remotely. No exploit exists.
GHSA
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause
ghsa_unreviewed·2026-07-13
CVE-2026-6850 [MEDIUM] CWE-1333 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser.. Mattermost Advisory ID: MMSA-2026-00658
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-13
Published