CVE-2026-8075
Mattermost Desktop App vulnerability analysis and mitigation

Overview

CVE-2026-8075 is a Denial of Service vulnerability in the Mattermost Desktop App caused by improper null checking when processing image headers in links. Any authenticated channel member can crash other members' Desktop App instances by posting a malicious link containing an embedded image with missing HTTP headers. Affected versions include ≤5.5.13, 6.0.2.x (before 6.0.3), and 6.2.x (before 6.2.1), with version 6.3.0 and later being unaffected. It was published on July 17, 2026, with Mattermost Advisory ID MMSA-2026-00668. The CVSS v3.1 base score is 6.5 (Medium) (GitHub Advisory, Mattermost Security).

Technical details

The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions): the Mattermost Desktop App fails to perform proper null checks when inspecting HTTP response headers associated with embedded images in posted links. When the Desktop App attempts to render a link preview containing an image that is missing one or more expected headers, the missing null check causes a crash (likely a null pointer dereference) in the client application. The attack vector is network-based, requires low privileges (any authenticated channel member), and no user interaction beyond the victim's app being open in the affected channel (GitHub Advisory).

Impact

Successful exploitation results in a crash of the Mattermost Desktop App for all channel members who view the malicious message, causing a denial of service to their client application. There is no impact on confidentiality or integrity — only availability is affected. An attacker with access to any shared channel can repeatedly trigger crashes, effectively preventing targeted users from using the Desktop App until they upgrade or the message is removed (GitHub Advisory, Mattermost Security).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.235%, indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable.

Exploitation steps

  1. Gain channel access: Authenticate to a Mattermost instance as any valid user and join or access a channel that includes the target victim(s) running a vulnerable Desktop App version.
  2. Craft a malicious link: Prepare or host a URL that serves an image response with one or more required HTTP headers intentionally omitted (e.g., missing Content-Type or Content-Length headers in the image response).
  3. Post the link: Post the crafted URL in the shared channel. The Mattermost server will generate a link preview, and the Desktop App of channel members will attempt to fetch and render the embedded image.
  4. Trigger the crash: When the vulnerable Desktop App processes the image response and encounters the missing header, the improper null check causes the application to crash, denying service to all affected channel members viewing the message (GitHub Advisory).

Indicators of compromise

  • Logs: Repeated unexpected crashes or unhandled exception logs in the Mattermost Desktop App logs around the time a specific message or link was posted in a channel.
  • Application Behavior: Multiple users in the same channel reporting simultaneous Desktop App crashes after a new message containing a link was posted.
  • Network: Outbound requests from the Desktop App to an unusual or external domain serving image content with atypical or missing HTTP response headers.
  • Channel Activity: Presence of a message containing an external link with an embedded image posted by an unfamiliar or low-trust user shortly before crash events were observed.

Mitigation and workarounds

Users should upgrade the Mattermost Desktop App to version 6.3.0, 6.2.1, or 5.13.6 (or later), which contain the fix for this vulnerability (Mattermost Security, GitHub Advisory). As a temporary workaround pending upgrade, administrators can implement access controls to restrict which users are permitted to post links in sensitive channels. Disabling automatic image preview loading in Desktop App settings, if available, may also reduce exposure until the patch is applied.

Additional resources


SourceThis report was generated using AI

Related Mattermost Desktop App vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9816HIGH8.3
  • Mattermost Desktop App logoMattermost Desktop App
  • mattermost-10.11
NoYesAug 17, 2026
CVE-2026-9859MEDIUM6.5
  • Mattermost Desktop App logoMattermost Desktop App
  • mattermost-10.11
NoYesAug 17, 2026
CVE-2026-16049MEDIUM4.3
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoNoAug 17, 2026
CVE-2026-9693LOW3.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesAug 17, 2026
CVE-2026-75587LOW3.3
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management