CVE-2026-75587
Received Received - Intake

Mattermost Desktop App Pre-Auth Secret Exposure in Diagnostics

Vulnerability report for CVE-2026-75587, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: Mattermost, Inc.

Description

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mattermost desktop_app to 6.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mattermost Desktop App versions up to 6.2.2.0 fail to redact a pre-authentication secret when generating a diagnostics report. This means the secret appears in plaintext in the diagnostics output, specifically in the Server Connectivity (Step-3) section. A local attacker with access to these files could extract the secret.

Detection Guidance

This vulnerability can be detected by inspecting diagnostics reports or log files for plaintext pre-auth secrets in the Server Connectivity (Step-3) output. Check for exposed secrets in files generated by Mattermost Desktop App versions <=6.2.2.0.

Impact Analysis

If you use Mattermost Desktop App versions <=6.2.2.0, an attacker with access to your diagnostics report or log files could obtain the plaintext pre-auth secret for your connected server. This could allow unauthorized access to server resources or data.

Compliance Impact

The vulnerability involves exposure of a pre-auth secret in diagnostics reports, which could lead to unauthorized access to server connections. This may impact compliance by potentially violating data protection requirements under GDPR or HIPAA if the exposed secret relates to user authentication or server connectivity involving protected health or personal data.

Mitigation Strategies

Update Mattermost Desktop App to version 6.2.2.0 or later to address the vulnerability. Remove any existing diagnostics reports or log files that may contain the plaintext pre-auth secret.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75587. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart