CVE-2026-10556
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Sep 14, 2026
Vendor
unknown
Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the instance via a crafted { {POST} } request to the public webhook endpoint.. Mattermost Advisory ID: MMSA-2026-00693