Description
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID: MMSA-2026-00717
Published: 2026-09-17
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: Insecure loading of plugin popout windows via downgraded URL schemes, enabling a network‑positioned attacker to force the client to use an insecure connection
Action: Upgrade
AI Analysis

Impact

Mattermost Desktop App versions up to 6.2.2.0 do not validate the URL scheme when determining whether a target URL is internal to the connected server. This flaw allows an attacker positioned on the same network to craft a link that uses a downgraded URL scheme, causing the client to load a plugin popout window over an insecure connection. The result is that a malicious plugin could be loaded without the user’s knowledge, potentially exposing sensitive data or enabling further compromise.

Affected Systems

The vulnerability affects the Mattermost Desktop App from the Mattermost vendor. All releases with a version number of 6.2.2.0 or earlier are impacted; newer releases beginning with 6.2.3.0 or 6.3.0 include the fix.

Risk and Exploitability

The CVSS score of 2.6 indicates low overall severity, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker who can supply a malicious link to a victim via the network, suggesting a network‑based attack vector. While the potential damage is limited, the flaw allows the attacker to force the application to use an insecure connection to load a plugin, which could lead to further exploitation if a malicious plugin is installed.

Generated by OpenCVE AI on September 17, 2026 at 20:51 UTC.

Remediation

Vendor Solution

Update Mattermost Desktop App to versions 6.3.0, 6.2.3.0 or higher.


OpenCVE Recommended Actions

  • Apply the Mattermost Desktop App update to version 6.3.0 or any 6.2.3.0 and above as prescribed by the vendor
  • Restrict network access to the Mattermost server so only trusted hosts can supply links that trigger plugin popouts, reducing the attacker’s ability to position themselves on the same network
  • Configure endpoint and network security controls to detect and block unexpected or insecure plugin loading activity

Generated by OpenCVE AI on September 17, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID: MMSA-2026-00717
Title Mattermost Desktop App plugin popout scheme validation bypass
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-17T19:22:50.101Z

Reserved: 2026-08-17T22:19:32.227Z

Link: CVE-2026-75588

cve-icon Vulnrichment

Updated: 2026-09-17T19:22:40.335Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:17:41.940

Modified: 2026-09-18T13:46:33.503

Link: CVE-2026-75588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-1287

    Improper Validation of Specified Type of Input