Arbitrary Code Execution Vulnerability in Mattermost Desktop App
CVE-2026-1046
7.6HIGH
What is CVE-2026-1046?
The Mattermost Desktop App contains a security flaw where various versions fail to properly validate help links. This vulnerability could allow a malicious Mattermost server to execute arbitrary executables on a user's system simply by clicking certain items within the Help menu. Users of versions 5.2.13.0 and earlier, as well as 6.0 and 6.2.0, should take caution and consider updating to mitigate potential security risks. For more detailed information, refer to the Mattermost Advisory at the provided link.
Affected Version(s)
Mattermost 0 <= 6.2.0
Mattermost 0 <= 5.2.13
Mattermost 6.1.0