CVE-2026-75587
Mattermost Desktop App vulnerability analysis and mitigation

Overview

CVE-2026-75587 is a credential disclosure vulnerability in the Mattermost Desktop App that fails to redact the pre-auth secret when generating a diagnostics report. Affected versions are Mattermost Desktop App ≤6.2.2.0 (all versions prior to 6.2.3/6.3.0). The flaw was published on August 17, 2026, with the GitHub Advisory (GHSA-jq35-5w25-hqv7) added on August 18, 2026, under Mattermost Advisory ID MMSA-2026-00716. It carries a CVSS v3.1 base score of 3.3 (Low) per NVD, and 3.6 (Low) per ENISA/GitHub Advisory (GitHub Advisory, Mattermost Security).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor): the Mattermost Desktop App does not sanitize or redact the pre-auth secret before writing it to diagnostics output. When a user generates a diagnostics report, the plaintext pre-auth secret configured for a connected Mattermost server is included in the "Server Connectivity (Step-3)" section of the report. An attacker with local read access to the diagnostics report or associated log files can trivially extract this secret without any special tooling. No public proof-of-concept exploit code has been identified (GitHub Advisory, Mattermost Security).

Impact

Successful exploitation allows a local attacker to obtain the plaintext pre-auth secret for a connected Mattermost server, which could be used to authenticate to that server or bypass pre-authentication controls. The impact is limited to confidentiality (low), with no integrity or availability consequences. The attack is constrained to the local system and requires access to the victim's diagnostics report or log files, limiting the blast radius but potentially enabling unauthorized server access if the secret is reused or shared (GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for this vulnerability. The NVD SSVC assessment confirms exploitation is "none" and the attack is not automatable. The EPSS score is approximately 0.104%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Mattermost Security).

Exploitation steps

  1. Local Access: Gain local access to a system where Mattermost Desktop App ≤6.2.2.0 is installed and configured with a pre-auth secret for a connected server.
  2. Trigger Diagnostics Report: Either wait for the user to generate a diagnostics report, or if already in possession of the user's session, trigger the diagnostics report generation from within the Mattermost Desktop App.
  3. Locate Report/Log Files: Navigate to the directory where Mattermost Desktop App stores diagnostics reports or log files (typically within the user's application data directory).
  4. Extract Pre-Auth Secret: Open the diagnostics report and inspect the "Server Connectivity (Step-3)" section to find the plaintext pre-auth secret.
  5. Use Secret: Use the extracted pre-auth secret to authenticate to the connected Mattermost server or bypass pre-authentication controls (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected access or copying of Mattermost Desktop App diagnostics report files (e.g., files in %APPDATA%\Mattermost on Windows or ~/.config/Mattermost on Linux/macOS) by processes or users other than the owning account.
  • Logs: Operating system audit logs showing unauthorized read access to Mattermost log or diagnostics files by non-owner accounts or processes.
  • Network: Unusual authentication attempts to Mattermost servers using pre-auth secrets from unexpected source IPs or user agents, potentially indicating credential reuse after extraction.

Mitigation and workarounds

Mattermost has released fixed versions 6.2.3.0 and 6.3.0 of the Desktop App, which redact the pre-auth secret from diagnostics output. Users should update to version 6.3.0 or later as the primary remediation. As an interim measure, restrict filesystem access to Mattermost diagnostics reports and log files to prevent unauthorized local access, and review any previously generated diagnostic reports to determine if pre-auth secrets have been exposed and rotate them if necessary (Mattermost Security, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Mattermost Desktop App vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9816HIGH8.3
  • Mattermost Desktop App logoMattermost Desktop App
  • mattermost-10.11
NoYesAug 17, 2026
CVE-2026-9859MEDIUM6.5
  • Mattermost Desktop App logoMattermost Desktop App
  • mattermost-10.11
NoYesAug 17, 2026
CVE-2026-16049MEDIUM4.3
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoNoAug 17, 2026
CVE-2026-9693LOW3.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesAug 17, 2026
CVE-2026-75587LOW3.3
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management