
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75587 is a credential disclosure vulnerability in the Mattermost Desktop App that fails to redact the pre-auth secret when generating a diagnostics report. Affected versions are Mattermost Desktop App ≤6.2.2.0 (all versions prior to 6.2.3/6.3.0). The flaw was published on August 17, 2026, with the GitHub Advisory (GHSA-jq35-5w25-hqv7) added on August 18, 2026, under Mattermost Advisory ID MMSA-2026-00716. It carries a CVSS v3.1 base score of 3.3 (Low) per NVD, and 3.6 (Low) per ENISA/GitHub Advisory (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor): the Mattermost Desktop App does not sanitize or redact the pre-auth secret before writing it to diagnostics output. When a user generates a diagnostics report, the plaintext pre-auth secret configured for a connected Mattermost server is included in the "Server Connectivity (Step-3)" section of the report. An attacker with local read access to the diagnostics report or associated log files can trivially extract this secret without any special tooling. No public proof-of-concept exploit code has been identified (GitHub Advisory, Mattermost Security).
Successful exploitation allows a local attacker to obtain the plaintext pre-auth secret for a connected Mattermost server, which could be used to authenticate to that server or bypass pre-authentication controls. The impact is limited to confidentiality (low), with no integrity or availability consequences. The attack is constrained to the local system and requires access to the victim's diagnostics report or log files, limiting the blast radius but potentially enabling unauthorized server access if the secret is reused or shared (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for this vulnerability. The NVD SSVC assessment confirms exploitation is "none" and the attack is not automatable. The EPSS score is approximately 0.104%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Mattermost Security).
%APPDATA%\Mattermost on Windows or ~/.config/Mattermost on Linux/macOS) by processes or users other than the owning account.Mattermost has released fixed versions 6.2.3.0 and 6.3.0 of the Desktop App, which redact the pre-auth secret from diagnostics output. Users should update to version 6.3.0 or later as the primary remediation. As an interim measure, restrict filesystem access to Mattermost diagnostics reports and log files to prevent unauthorized local access, and review any previously generated diagnostic reports to determine if pre-auth secrets have been exposed and rotate them if necessary (Mattermost Security, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."