CVE-2026-2476

Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:ms_teams:*:*:*:*:*:mattermost:*:*

History

20 Mar 2026, 18:29

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Mattermost
Mattermost ms Teams
CPE cpe:2.3:a:mattermost:ms_teams:*:*:*:*:*:mattermost:*:*
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
Summary
  • (es) Las versiones &lt;=2.0.3.0 de los plugins de Mattermost no logran enmascarar correctamente los valores de configuración sensibles, lo que permite a un atacante con acceso a los paquetes de soporte obtener la configuración original del plugin a través de datos de configuración exportados. ID de Aviso de Mattermost: MMSA-2026-00606

16 Mar 2026, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:19

Updated : 2026-03-20 18:29


NVD link : CVE-2026-2476

Mitre link : CVE-2026-2476

CVE.ORG link : CVE-2026-2476


JSON object : View

Products Affected

mattermost

  • ms_teams
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo