Description
Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall IPC message. Mattermost Advisory ID: MMSA-2026-00699
Published: 2026-09-17
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Call Disruption
Action: Patch
AI Analysis

Impact

The Mattermost Desktop App fails to validate the IPC sender in its leaveCall handler. A malicious or compromised Mattermost server, or a user with script access to a connected server view, can send an IPC message that disconnects an active call on a different server. This flaw effectively allows an attacker to interrupt ongoing voice and video communications, resulting in a denial of service for the call participants. The weakness is a classic example of missing access control and is classified as CWE‑346.

Affected Systems

Affected versions of the Mattermost Desktop App are all releases 6.2.2.0 and earlier, including 6.2.0, 6.2.1, and 6.2.2.0. The vendor recommends upgrading to any version 6.3.0 or later, or 6.2.3.0 or later, where the IPC sender validation has been added.

Risk and Exploitability

The CVSS score for this issue is 3.8, giving it a low–moderate severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is currently uncertain. The attack requires control of a Mattermost server or the ability to inject scripts into a server view, which suggests the risk is higher in environments with compromised servers or in which users have elevated script permissions. Even with a low damage profile, the denial of service could disrupt collaboration in critical teams, so it remains a relevant concern for organizations that rely heavily on Mattermost calls.

Generated by OpenCVE AI on September 17, 2026 at 20:30 UTC.

Remediation

Vendor Solution

Update Mattermost Desktop App to versions 6.3.0, 6.2.3.0 or higher.


OpenCVE Recommended Actions

  • Update Mattermost Desktop App to any version 6.3.0, 6.2.3.0 or higher to add IPC sender validation.
  • Restrict script access to server views and enforce strict access controls to limit the ability of compromised servers to issue IPC messages.
  • Monitor call stability and verify that all users are running the patched client to mitigate potential disruption.

Generated by OpenCVE AI on September 17, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall IPC message. Mattermost Advisory ID: MMSA-2026-00699
Title Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-17T19:18:45.112Z

Reserved: 2026-06-15T14:05:20.532Z

Link: CVE-2026-12284

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:17:21.993

Modified: 2026-09-18T13:46:33.503

Link: CVE-2026-12284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses