CVE-2026-6517

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_desktop:*:-:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*

History

16 Jun 2026, 16:54

Type Values Removed Values Added
First Time Mattermost
Mattermost mattermost Desktop
CPE cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_desktop:*:-:*:*:*:*:*:*
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory

15 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-15 14:16

Updated : 2026-06-17 11:00


NVD link : CVE-2026-6517

Mitre link : CVE-2026-6517

CVE.ORG link : CVE-2026-6517


JSON object : View

Products Affected

mattermost

  • mattermost_desktop
CWE
CWE-522

Insufficiently Protected Credentials