Mattermost Desktop App Vulnerability Exposes User Credentials
CVE-2026-6517
6.3MEDIUM
What is CVE-2026-6517?
The Mattermost Desktop App has a vulnerability that allows unauthorized access to user NTLM credentials by failing to restrict the list of domains to which these credentials are forwarded. This issue arises when the image proxy is disabled, enabling an attacker to embed an image linking to an external server. As a result, user credentials can be intercepted, significantly compromising data security and user privacy.
Affected Version(s)
Mattermost 0 <= 5.5.13
Mattermost 6.2.0
Mattermost 5.13.6.0