
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1046 is a help link validation flaw in the Mattermost Desktop App that allows a malicious Mattermost server to execute arbitrary executables on a user's system when the user clicks certain items in the Help menu. It is tracked under Mattermost Advisory ID MMSA-2026-00577 and affects Desktop App versions 6.0.0–6.0.2 and 5.13.2 and below. The vulnerability was published on February 16, 2026, with a patch released shortly after. It carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Red Hat).
The root cause is classified as CWE-939 (Improper Authorization in Handler for Custom URL Scheme): the Desktop App fails to validate or sanitize help links provided by the connected Mattermost server before acting on them. A malicious or compromised server can craft help menu URLs that, when clicked by a user, cause the Electron-based desktop client to invoke arbitrary executables on the host operating system rather than opening a legitimate web resource. Exploitation requires network access to a Mattermost server the victim trusts, and user interaction (clicking a Help menu item), but no special privileges on the server are needed (Feedly, Mattermost Security).
Successful exploitation allows an attacker controlling a Mattermost server to execute arbitrary binaries on any connected desktop client whose user clicks a malicious help link, resulting in a high integrity impact on the victim's system. This could facilitate unauthorized code execution, installation of malware or backdoors, and data theft, potentially affecting all users of an organization connected to a compromised server. Confidentiality and availability are not directly impacted per the CVSS scoring, but secondary consequences of arbitrary execution (e.g., ransomware, credential stealers) could extend the blast radius significantly (Feedly).
file://, ms-msdt:, or similar) pointing to an attacker-controlled binary or script on the victim's system.cmd.exe, powershell.exe, bash, python, or unusual binaries) shortly after a user interacts with the Help menu.%APPDATA%, /tmp, ~/) around the time of Help menu interaction, particularly scripts or executables not associated with Mattermost.Mattermost has released patched versions addressing this vulnerability: update to 5.13.3 or later (for users on the 5.x branch) or 6.0.3 or later (for users on the 6.x branch). No configuration-based workaround is documented; upgrading is the recommended remediation. As an interim measure, organizations should restrict user connections to untrusted or unverified Mattermost servers and advise users to avoid clicking Help menu items until patched (Mattermost Security, Feedly).
The vulnerability received brief coverage on Mastodon via The Hacker Wire and was mentioned in The Hacker News weekly security recap for May 2026, indicating moderate community awareness (The Hacker News). A technical write-up was published at infinitsec.net shortly after disclosure, describing the arbitrary application execution mechanism (infinitsec). Overall community reaction has been measured, consistent with the absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."