CVE-2026-75587
- EPSS 0.1%
- Veröffentlicht 17.08.2026 22:09:49
- Zuletzt bearbeitet 19.08.2026 15:53:15
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret confi...
CVE-2026-8075
- EPSS 0.24%
- Veröffentlicht 17.07.2026 10:05:06
- Zuletzt bearbeitet 30.07.2026 14:44:35
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded ...
CVE-2026-9602
- EPSS 0.24%
- Veröffentlicht 17.07.2026 10:03:26
- Zuletzt bearbeitet 30.07.2026 14:38:53
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a mal...
CVE-2026-8683
- EPSS 0.2%
- Veröffentlicht 15.06.2026 14:06:21
- Zuletzt bearbeitet 16.06.2026 17:18:55
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a ver...
CVE-2026-6517
- EPSS 0.19%
- Veröffentlicht 15.06.2026 13:55:25
- Zuletzt bearbeitet 16.06.2026 16:54:47
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other u...
CVE-2026-3471
- EPSS 0.18%
- Veröffentlicht 18.05.2026 08:45:44
- Zuletzt bearbeitet 05.06.2026 17:43:51
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javas...
CVE-2026-4643
- EPSS 0.17%
- Veröffentlicht 18.05.2026 08:43:34
- Zuletzt bearbeitet 05.06.2026 17:44:47
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking ...
CVE-2026-1628
- EPSS 0.14%
- Veröffentlicht 02.03.2026 13:24:21
- Zuletzt bearbeitet 05.03.2026 16:07:40
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an...
CVE-2026-1046
- EPSS 0.24%
- Veröffentlicht 16.02.2026 12:10:38
- Zuletzt bearbeitet 23.03.2026 17:27:17
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisor...
CVE-2025-13326
- EPSS 0.11%
- Veröffentlicht 17.12.2025 18:14:14
- Zuletzt bearbeitet 18.12.2025 19:47:06
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.