Sensitive Data Exposure in Mattermost Desktop App by Mattermost
CVE-2026-75587
3.6LOW
What is CVE-2026-75587?
The Mattermost Desktop App versions up to 6.2, including 6.2.2.0, have a critical issue that fails to redact the pre-authentication secret in diagnostics reports. This vulnerability enables a local attacker with access to these reports or the log files to extract the plaintext pre-auth secret associated with a connected server, particularly through the insights provided in the Server Connectivity diagnostics output. It is crucial for users to be aware of this risk to protect sensitive credentials.
Affected Version(s)
Mattermost 0 <= 6.2.2
Mattermost 6.3.0
Mattermost 6.2.3.0