Impact
Mattermost Desktop App versions up to 6.2.2.0 generate diagnostics reports that expose the plaintext pre-authentication secret configured for a Mattermost server. This data is readable by any local user who can access a diagnostics report or associated log files, allowing the attacker to obtain credentials necessary to authenticate to the Mattermost server and potentially gain broader access or perform unauthorized actions.
Affected Systems
Mattermost Desktop App, version 6.2.2.0 and earlier, should be updated to 6.3.0, 6.2.3.0 or newer.
Risk and Exploitability
The vulnerability has a CVSS score of 3.6, indicating low severity, and no EPSS data is available; the vulnerability is not listed in CISA KEV. Because the attack requires local access to diagnostics files, the exploitation window is limited to situations where log or report data remains on the machine. Nonetheless, any local attacker can read the pre-auth secret from the exported diagnostics, making the risk moderate in environments where logs are retained or not protected.
OpenCVE Enrichment