
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2578 is an information disclosure vulnerability in Mattermost Server that allows authenticated channel members to access the contents of burn-on-read (self-destructing) messages that should have been redacted upon deletion. The flaw affects Mattermost Server versions 11.3.x ≤ 11.3.0, and was disclosed on March 16, 2026, with a patch released on March 18, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) and is tracked under Mattermost Advisory ID MMSA-2026-00579 (Red Hat CVE, Mattermost Security).
The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data). When a burn-on-read post is deleted in Mattermost, the server fails to preserve the redacted state of the message content in the WebSocket post deletion event it broadcasts to channel members. As a result, the full, unredacted message content is transmitted over the WebSocket connection to all channel members at the moment of deletion, rather than a sanitized or empty payload. Exploitation requires only that the attacker be an authenticated member of the channel where the burn-on-read message was sent (Red Hat CVE, Mattermost Security).
Successful exploitation results in unauthorized disclosure of confidential message contents that were explicitly intended to be ephemeral and self-destructing. An authenticated channel member can intercept the WebSocket deletion event to read burn-on-read messages in their entirety, undermining the confidentiality guarantee of this feature. There is no integrity or availability impact, and the scope is limited to the channel context in which the attacker holds membership (Red Hat CVE).
wss://<host>/api/v4/websocket) using a WebSocket client or browser developer tools to monitor real-time events.post_deleted WebSocket event payload, which improperly includes the full, unredacted message content instead of a sanitized version.post_deleted events without normal user interaction patterns.post_deleted WebSocket events for burn-on-read posts, especially from non-standard clients or scripts.Mattermost released a patch in version 11.3.1 on March 18, 2026; administrators should upgrade to this version or later immediately (Mattermost Security). As a temporary workaround for organizations unable to patch immediately, restrict channel membership to trusted users and monitor WebSocket traffic for anomalous post deletion event consumption. Review access logs to identify any potential unauthorized access to burn-on-read message contents prior to patching.
The vulnerability was picked up by standard security advisory channels including Red Hat, openSUSE security announcements, and Linux security advisory aggregators shortly after disclosure (Red Hat CVE, openSUSE Advisory). No notable researcher commentary or significant social media discussion has been observed, consistent with the medium severity rating and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."