What is CVE-2026-10600?
CVE-2026-10600 is a vulnerability in Mattermost where server-side document content extraction fails to bound time and resource consumption. This allows an authenticated user with file-upload permission to degrade file uploads for all users on the server. Updating the affected versions is recommended.
Azərbaycanca: CVE-2026-10600 Mattermost serverin sənəd məzmunu çıxarılması (content extraction) zamanı vaxt və resurs istehlakını məhdudlaşdırmaması ilə bağlı zəiflikdir. Bu, fayl yükləmə icazəsi olan autentifikasiya olunmuş istifadəçiyə serverdəki bütün istifadəçilər üçün fayl yükləmə funksiyasını deqradasiya etməyə imkan verir. Təsirə məruz qalan versiyaları yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Mattermost
FAQ2
Who can exploit CVE-2026-10600?
An authenticated user with file-upload permission.
What is the impact of CVE-2026-10600 on the Mattermost server?
It degrades the file upload function for all users on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.