CVE-2026-4643
Mattermost Desktop App vulnerability analysis and mitigation

Overview

CVE-2026-4643 is a denial-of-service vulnerability in the Mattermost Desktop App that allows a malicious server or plugin to crash the desktop client by invoking window.close() in the renderer context. It affects Mattermost Desktop App versions up to and including 5.4.13.0, versions 6.0.0–6.0.1, and versions 6.1.0 up to (excluding) 6.2.0. The vulnerability was disclosed on May 18, 2026, with initial analysis completed by NIST on June 5, 2026. It carries a CVSS v3.1 base score of 3.5 (Low), assigned by Mattermost, Inc. (GitHub Advisory, Mattermost Security).

Technical details

The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions): the Mattermost Desktop App fails to prevent server-rendered content in the Electron renderer context from invoking window.close(), which closes the underlying application view. Because the app does not validate or restrict this browser API call from untrusted server-side or plugin-supplied content, a malicious Mattermost server or a compromised/malicious plugin can trigger the closure of the application window, effectively crashing the client. Exploitation requires network access, low privileges (an authenticated user account), and user interaction (the user must be connected to the malicious server) (GitHub Advisory, Mattermost Security).

Impact

Successful exploitation results in a denial-of-service condition at the client level — the Mattermost Desktop App crashes for the affected user. There is no impact on confidentiality or integrity; only availability is affected (rated Low in scope). The impact is limited to individual desktop clients connecting to a malicious or compromised server, with no evidence of lateral movement potential or data exposure (GitHub Advisory, Mattermost Security).

Exploitation steps

  1. Setup a malicious Mattermost server or plugin: An attacker operates or compromises a Mattermost server, or develops/distributes a malicious Mattermost plugin that injects custom JavaScript into server-rendered content.
  2. Lure a victim to connect: The attacker convinces a target user running a vulnerable Mattermost Desktop App (≤5.4.13.0, 6.0.0–6.0.1, or 6.1.x < 6.2.0) to connect to the attacker-controlled server.
  3. Inject window.close() call: The malicious server or plugin delivers content to the desktop client's Electron renderer that includes or triggers a window.close() JavaScript call.
  4. Crash the desktop client: Because the app does not restrict this API call from renderer context, the application view closes, crashing the Mattermost Desktop App and causing a denial-of-service for that user (GitHub Advisory, Mattermost Security).

Indicators of compromise

  • Process: Unexpected termination of the Mattermost Desktop App process without user-initiated close action.
  • Logs: Application crash logs or Electron renderer error logs referencing unexpected window.close() invocation or abrupt view closure.
  • Network: Connections from the Mattermost Desktop App to unfamiliar or unauthorized Mattermost server addresses prior to crash events.
  • File System: Presence of unfamiliar or unvetted Mattermost plugins in the plugin directory that may contain malicious JavaScript.

Mitigation and workarounds

Users should update the Mattermost Desktop App to version 6.2.0 or later, which addresses this vulnerability. As a workaround, organizations should restrict plugin installation to trusted, vetted sources only and audit any third-party plugins for malicious code that could invoke window.close(). Users should also avoid connecting to untrusted or unknown Mattermost servers (Mattermost Security, GitHub Advisory).

Community reactions

The vulnerability received limited public attention given its low severity rating. A brief mention was noted on Bluesky via an automated CVE tracking account, and standard aggregator sites (Vulners, VulDB, CVEFeed) indexed the advisory shortly after disclosure. No significant researcher commentary or media coverage has been identified (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Mattermost Desktop App vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6517HIGH7.7
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesJun 15, 2026
CVE-2026-8683MEDIUM6.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesJun 15, 2026
CVE-2026-3471MEDIUM6.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesMay 18, 2026
CVE-2026-1628MEDIUM4.6
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesMar 02, 2026
CVE-2026-4643LOW3.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesMay 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management