CVE-2026-4635

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persistent notification message between the server deleting existing persistent notifications and archiving the channel.. Mattermost Advisory ID: MMSA-2026-00637
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

22 May 2026, 17:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-22 11:16

Updated : 2026-05-22 17:20


NVD link : CVE-2026-4635

Mitre link : CVE-2026-4635

CVE.ORG link : CVE-2026-4635


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')