Description
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost Advisory ID: MMSA-2026-00678
Published: 2026-07-17
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost Desktop App does not validate payloads received from the Web App via IPC, allowing an adversary that controls the backing Mattermost server to send malformed data that crashes the desktop client. This failure of input validation (CWE‑400) results in a denial‑of‑service condition where the application terminates unexpectedly, disrupting user workflow and potentially causing data loss. The vulnerability does not expose any data or provide code execution, but it can be leveraged to degrade availability for users on the affected installations.

Affected Systems

Mattermost Desktop App, versions 6.2 and earlier, 6.0.2, and 5.6.13.0 and older, as identified by the Mattermost CNA. Users of these releases should verify the installed version and plan to upgrade to 6.3.0, 6.2.1.0, 5.13.7.0 or later.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation campaigns. The likely attack vector requires an attacker to be in control of a Mattermost server that serves the target desktop client, exploiting the IPC channel over the local network or user’s machine. Since no privilege escalation is required, any user connected to a malicious server could experience the crash, but the impact remains limited to the desktop application rather than system compromise.

Generated by OpenCVE AI on July 31, 2026 at 00:32 UTC.

Remediation

Vendor Solution

Update Mattermost Desktop App to versions 6.3.0, 6.2.1.0, 5.13.7.0 or higher.


OpenCVE Recommended Actions

  • Update Mattermost Desktop App to version 6.3.0, 6.2.1.0, 5.13.7.0 or newer using the patch available at https://mattermost.com/security-updates
  • Verify that all Mattermost servers utilized by your organization are trusted and free from compromise or malicious configuration changes
  • Implement network segmentation or firewall rules to restrict IPC traffic between the Mattermost Desktop App and untrusted servers when upgrading is delayed

Generated by OpenCVE AI on July 31, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Fri, 17 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost Advisory ID: MMSA-2026-00678
Title Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-17T12:54:25.366Z

Reserved: 2026-05-26T15:42:07.316Z

Link: CVE-2026-9602

cve-icon Vulnrichment

Updated: 2026-07-17T12:54:22.176Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:45:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption