Impact
The Mattermost Desktop App fails to validate the IPC sender in its leaveCall handler. A malicious or compromised Mattermost server, or a user with script access to a connected server view, can send an IPC message that disconnects an active call on a different server. This flaw effectively allows an attacker to interrupt ongoing voice and video communications, resulting in a denial of service for the call participants. The weakness is a classic example of missing access control and is classified as CWE‑346.
Affected Systems
Affected versions of the Mattermost Desktop App are all releases 6.2.2.0 and earlier, including 6.2.0, 6.2.1, and 6.2.2.0. The vendor recommends upgrading to any version 6.3.0 or later, or 6.2.3.0 or later, where the IPC sender validation has been added.
Risk and Exploitability
The CVSS score for this issue is 3.8, giving it a low–moderate severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is currently uncertain. The attack requires control of a Mattermost server or the ability to inject scripts into a server view, which suggests the risk is higher in environments with compromised servers or in which users have elevated script permissions. Even with a low damage profile, the denial of service could disrupt collaboration in critical teams, so it remains a relevant concern for organizations that rely heavily on Mattermost calls.
OpenCVE Enrichment