Mattermost · Mattermost · CVE-2026-10080
**Name of the Vulnerable Software and Affected Versions**
Mattermost versions 11.7.0 through 11.7.6
Mattermost versions 10.11.0 through 10.11.21
Mattermost versions 11.8.0 through 11.8.3
**Description**
An issue exists where the software fails to validate WebSocket command field types. This allows an authenticated user to crash the plugin process, resulting in a denial of service for all Boards users. The flaw is triggered by sending a `custom focalboard SUBSCRIBE TEAM` message containing a non-string `teamId` variable.
**Recommendations**
Update Mattermost versions 11.7.0 through 11.7.6 to a version newer than 11.7.6.
Update Mattermost versions 10.11.0 through 10.11.21 to a version newer than 10.11.21.
Update Mattermost versions 11.8.0 through 11.8.3 to a version newer than 11.8.3.