Sensitive Credential Exposure in Mattermost by Mattermost
CVE-2026-6346
8.7HIGH
What is CVE-2026-6346?
Mattermost versions 11.5.x up to 11.5.1, 10.11.x up to 10.11.13, and 11.4.x up to 11.4.3 are affected by a vulnerability that fails to properly sanitize sensitive configuration fields included in generated support packets. This oversight can enable a Mattermost System Administrator, or anyone with access to a support packet, to potentially extract sensitive credentials in plaintext, leading to severe security risks. For more details, refer to the Mattermost Security Advisory.
Affected Version(s)
Mattermost 11.5.0 <= 11.5.1
Mattermost 10.11.0 <= 10.11.13
Mattermost 11.4.0 <= 11.4.3