Executive brief
Mattermost is a collaboration and messaging platform used by organizations for internal communication. A vulnerability in certain versions allows a logged-in user to crash the messaging server by carefully timing the creation of a notification while a channel is being archived. This results in a denial-of-service, preventing all users from accessing the platform until the service is restored.
Technical details
A race condition (CWE-362) exists in Mattermost Server due to improper synchronization when archiving channels. The application fails to archive a channel before removing persistent notifications. An authenticated attacker can exploit this by timing the creation of a persistent notification message to occur exactly between the deletion of existing notifications and the archiving of the channel. This synchronization error triggers a server crash. The issue is resolved in versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, and 10.11.15.
Affected products
- Mattermost Mattermost Server 11.6.0, 11.5.0-11.5.3, 11.4.0-11.4.4, 10.11.0-10.11.14
Timeline
- 2026-05-22: advisory: Mattermost Advisory MMSA-2026-00637 published
- 2026-05-22: disclosed: CVE-2026-4635 published to NVD