
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6517 is a credential interception vulnerability in the Mattermost Desktop App that allows authenticated users to steal other users' NTLM credentials by embedding malicious images in messages. The flaw affects Mattermost Desktop App versions ≤6.1 and ≤5.5.13, and was disclosed on June 15, 2026, with Mattermost Advisory ID MMSA-2026-00651. The vulnerability has a CNA-assigned CVSS v3.1 base score of 6.3 (Medium), while NVD's independent assessment rates it 7.7 (High) (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-522 (Insufficiently Protected Credentials): the Mattermost Desktop App fails to enforce an allowlist of trusted domains when forwarding NTLM authentication credentials, meaning credentials can be sent to arbitrary external servers. An attacker exploits this by embedding an image in a Mattermost message that points to an attacker-controlled external web server; when a victim's Desktop App renders the message, it automatically forwards NTLM credentials to the external host without restriction. This attack requires no user interaction beyond the victim viewing the message, but does require the target Mattermost server to have the image proxy feature disabled — a precondition that is not uncommon in self-hosted deployments (GitHub Advisory, Mattermost Security).
Successful exploitation results in high confidentiality impact: an attacker can capture NTLM credentials (hashes) of other users on the same Mattermost server. These captured credentials can be used in pass-the-hash attacks, credential stuffing, or lateral movement within corporate Windows environments, potentially enabling broader network compromise. There is no integrity or availability impact from the vulnerability itself, but the downstream consequences of stolen Windows domain credentials can be severe (GitHub Advisory, Mattermost Security).
).Upgrade the Mattermost Desktop App to version 6.2.0 or later (for the 6.x branch) or 5.13.6.0 or later (for the 5.x branch), as these versions enforce proper domain allowlisting for NTLM credential forwarding (Mattermost Security, GitHub Advisory). As an immediate workaround, enable the image proxy feature on the Mattermost server, which prevents the Desktop App from making direct connections to external image URLs and thus blocks credential forwarding to untrusted domains. Organizations should also audit Mattermost server configurations to confirm image proxy status and restrict posting permissions where feasible until patching is complete.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."