CVE-2026-4915: Server panic via outgoing webhook responses
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before processing, which allows an authenticated user to cause a denial of service (server process termination) via a crafted webhook callback response containing a null attachment entry.. Mattermost Advisory ID: MMSA-2026-00641
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4915?
CVE-2026-4915 has a medium severity score of 6.5.
How do I fix CVE-2026-4915?
To fix CVE-2026-4915, update Mattermost to versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, 10.11.15 or higher.
What does CVE-2026-4915 affect?
CVE-2026-4915 affects versions of Mattermost Server including 11.6.x, 11.5.x, 11.4.x, and 10.11.x.
What type of vulnerability is CVE-2026-4915?
CVE-2026-4915 is a denial of service vulnerability caused by server panic from unfiltered outgoing webhook responses.
Who is impacted by CVE-2026-4915?
Authenticated users of vulnerable Mattermost versions can exploit CVE-2026-4915 leading to server process termination.