Burn-on-Read Message Vulnerability in Mattermost by Mattermost
CVE-2026-2578
4.3MEDIUM
What is CVE-2026-2578?
In Mattermost versions 11.3.x up to 11.3.0, a flaw exists that permits channel members to access unrevealed content of burn-on-read messages even after these messages are deleted. This occurs because the application fails to maintain the intended redacted state of these messages during the deletion process, allowing unauthorized access through WebSocket post deletion events. This opens up risks concerning the confidentiality of sensitive information shared through burn-on-read messaging features.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 11.3.0
Mattermost 11.4.0
Mattermost 11.3.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Joshua Rogers