Sensitive Data Exposure in Mattermost Desktop App by Mattermost
CVE-2026-75587

3.6LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
17 August 2026

What is CVE-2026-75587?

The Mattermost Desktop App versions up to 6.2, including 6.2.2.0, have a critical issue that fails to redact the pre-authentication secret in diagnostics reports. This vulnerability enables a local attacker with access to these reports or the log files to extract the plaintext pre-auth secret associated with a connected server, particularly through the insights provided in the Server Connectivity diagnostics output. It is crucial for users to be aware of this risk to protect sensitive credentials.

Affected Version(s)

Mattermost 0 <= 6.2.2

Mattermost 6.3.0

Mattermost 6.2.3.0

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Juho Forsén
.