CVE-2026-4635: Persistent notification timing attack causing server denial of service
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persistent notification message between the server deleting existing persistent notifications and archiving the channel.. Mattermost Advisory ID: MMSA-2026-00637
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4635?
CVE-2026-4635 has a medium severity rating of 6.5.
What systems are affected by CVE-2026-4635?
CVE-2026-4635 affects Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, and 10.11.x <= 10.11.14.
What kind of attack is described in CVE-2026-4635?
CVE-2026-4635 describes a persistent notification timing attack that can cause server denial of service.
How do I fix CVE-2026-4635?
To fix CVE-2026-4635, update Mattermost to versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, 10.11.15 or higher.
What is the potential impact of CVE-2026-4635?
The potential impact of CVE-2026-4635 is that an authenticated user can crash the server.