Mattermost Desktop App Vulnerability Exposes User Credentials
CVE-2026-6517

6.3MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
15 June 2026

What is CVE-2026-6517?

The Mattermost Desktop App has a vulnerability that allows unauthorized access to user NTLM credentials by failing to restrict the list of domains to which these credentials are forwarded. This issue arises when the image proxy is disabled, enabling an attacker to embed an image linking to an external server. As a result, user credentials can be intercepted, significantly compromising data security and user privacy.

Affected Version(s)

Mattermost 0 <= 5.5.13

Mattermost 6.2.0

Mattermost 5.13.6.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

falke
.