
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2476 is an information disclosure vulnerability in Mattermost Plugins (versions ≤2.0.3.0) that fails to properly mask sensitive configuration values in exported support packet data. An authenticated attacker with access to support packets can retrieve original, unmasked plugin settings — including credentials and API keys — from the exported configuration data. The vulnerability was published on March 16, 2026, with a patch made available on March 20, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) and is tracked under Mattermost Advisory ID MMSA-2026-00606 (Feedly, Mattermost Security).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Mattermost Plugins fail to apply proper masking or redaction to sensitive configuration fields — such as API keys and authentication credentials — when generating support packets for export. An authenticated attacker with low privileges who has access to these support packets can parse the exported configuration data to recover plaintext sensitive values. No user interaction is required, and the attack is conducted over the network (Feedly).
Successful exploitation results in the exposure of sensitive plugin configuration data, including authentication credentials, API keys, and other secrets stored in plugin settings. The confidentiality impact is rated low-to-moderate in scope, as the attacker must already have access to support packets, limiting the blast radius. However, exposed credentials could enable lateral movement or unauthorized access to integrated third-party services and systems (Feedly).
Mattermost has released a patch addressing this vulnerability; users should upgrade Mattermost Plugins to a version greater than 2.0.3.0 (patch available as of March 20, 2026). As an interim workaround, restrict access to support packet generation and storage to authorized administrators only. Organizations should also review any previously generated support packets for unintended exposure of sensitive configuration data and rotate any credentials or API keys that may have been included (Mattermost Security, Feedly).
The vulnerability received limited public attention, with brief mentions on social platforms such as Bluesky and Mastodon shortly after disclosure. No significant researcher commentary or major media coverage has been identified. The Red Hat CVE advisory page and openSUSE security announcement list also referenced the vulnerability, indicating routine tracking by downstream distributors (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."