Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Desktop App to versions 6.3.0, 6.2.3.0 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 17 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716 | |
| Title | Plaintext pre-auth secret exposure via Desktop App diagnostics report | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-08-18T14:20:26.801Z
Reserved: 2026-08-17T22:07:53.714Z
Link: CVE-2026-75587
Updated: 2026-08-18T14:20:03.397Z
Status : Undergoing Analysis
Published: 2026-08-17T23:16:52.820
Modified: 2026-08-18T15:17:13.580
Link: CVE-2026-75587
No data.
OpenCVE Enrichment
Updated: 2026-08-18T01:00:05Z