CVE-2026-1046

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*

History

23 Mar 2026, 17:27

Type Values Removed Values Added
First Time Mattermost
Mattermost mattermost Desktop
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
CPE cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*

18 Feb 2026, 17:52

Type Values Removed Values Added
Summary
  • (es) Las versiones &lt;=6.0 6.2.0 5.2.13.0 de la Aplicación de escritorio Mattermost no validan los enlaces de ayuda, lo que permite que un servidor Mattermost malicioso ejecute ejecutables arbitrarios en el sistema de un usuario al hacer clic el usuario en ciertos elementos del menú de Ayuda. ID de aviso de Mattermost: MMSA-2026-00577

16 Feb 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-16 13:16

Updated : 2026-03-23 17:27


NVD link : CVE-2026-1046

Mitre link : CVE-2026-1046

CVE.ORG link : CVE-2026-1046


JSON object : View

Products Affected

mattermost

  • mattermost_desktop
CWE
CWE-939

Improper Authorization in Handler for Custom URL Scheme