Junglewise Threat Intelligence

CVE-2026-4635: Mattermost Server race condition in channel archiving

CVE-2026-4635 · Severity: medium · CVSS 6.5 · Published 2026-05-22

Technologies: Mattermost Server, github.com/mattermost/mattermost-server (Go). Vendors: Mattermost, Go.

Executive brief

Mattermost is a collaboration and messaging platform used by organizations for internal communication. A vulnerability in certain versions allows a logged-in user to crash the messaging server by carefully timing the creation of a notification while a channel is being archived. This results in a denial-of-service, preventing all users from accessing the platform until the service is restored.

Technical details

A race condition (CWE-362) exists in Mattermost Server due to improper synchronization when archiving channels. The application fails to archive a channel before removing persistent notifications. An authenticated attacker can exploit this by timing the creation of a persistent notification message to occur exactly between the deletion of existing notifications and the archiving of the channel. This synchronization error triggers a server crash. The issue is resolved in versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, and 10.11.15.

Affected products

  • Mattermost Mattermost Server 11.6.0, 11.5.0-11.5.3, 11.4.0-11.4.4, 10.11.0-10.11.14

Timeline

  • 2026-05-22: advisory: Mattermost Advisory MMSA-2026-00637 published
  • 2026-05-22: disclosed: CVE-2026-4635 published to NVD

References

Related threats