Description
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
Published: 2026-08-17
Score: 3.6 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update Mattermost Desktop App to versions 6.3.0, 6.2.3.0 or higher.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 17 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
Title Plaintext pre-auth secret exposure via Desktop App diagnostics report
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-17T22:09:49.590Z

Reserved: 2026-08-17T22:07:53.714Z

Link: CVE-2026-75587

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T23:16:52.820

Modified: 2026-08-17T23:16:52.820

Link: CVE-2026-75587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses