Description
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
Published: 2026-08-17
Score: 3.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost Desktop App versions up to 6.2.2.0 generate diagnostics reports that expose the plaintext pre-authentication secret configured for a Mattermost server. This data is readable by any local user who can access a diagnostics report or associated log files, allowing the attacker to obtain credentials necessary to authenticate to the Mattermost server and potentially gain broader access or perform unauthorized actions.

Affected Systems

Mattermost Desktop App, version 6.2.2.0 and earlier, should be updated to 6.3.0, 6.2.3.0 or newer.

Risk and Exploitability

The vulnerability has a CVSS score of 3.6, indicating low severity, and no EPSS data is available; the vulnerability is not listed in CISA KEV. Because the attack requires local access to diagnostics files, the exploitation window is limited to situations where log or report data remains on the machine. Nonetheless, any local attacker can read the pre-auth secret from the exported diagnostics, making the risk moderate in environments where logs are retained or not protected.

Generated by OpenCVE AI on August 18, 2026 at 00:46 UTC.

Remediation

Vendor Solution

Update Mattermost Desktop App to versions 6.3.0, 6.2.3.0 or higher.


OpenCVE Recommended Actions

  • Update Mattermost Desktop App to version 6.3.0 or 6.2.3.0 and later.
  • Configure file system permissions to restrict access to diagnostics logs to only the user running the app.
  • Configure the app or audit logs to delete or archive diagnostics reports after a short retention period.

Generated by OpenCVE AI on August 18, 2026 at 00:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 19 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Desktop
CPEs cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Desktop

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 17 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
Title Plaintext pre-auth secret exposure via Desktop App diagnostics report
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

Mattermost Mattermost Mattermost Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-18T14:20:26.801Z

Reserved: 2026-08-17T22:07:53.714Z

Link: CVE-2026-75587

cve-icon Vulnrichment

Updated: 2026-08-18T14:20:03.397Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T23:16:52.820

Modified: 2026-08-19T15:53:15.973

Link: CVE-2026-75587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T01:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor