Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Desktop App to versions 6.1.0, 6.0.3.0, 5.13.3.0 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Mon, 23 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Desktop
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Desktop
|
Tue, 17 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Feb 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 16 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577 | |
| Title | Arbitrary application execution via unvalidated server-controlled URLs in Help menu | |
| Weaknesses | CWE-939 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-02-17T17:05:58.569Z
Reserved: 2026-01-16T16:24:48.693Z
Link: CVE-2026-1046
Updated: 2026-02-17T16:42:13.057Z
Status : Analyzed
Published: 2026-02-16T13:16:00.793
Modified: 2026-03-23T17:27:17.083
Link: CVE-2026-1046
No data.
OpenCVE Enrichment
Updated: 2026-04-18T12:15:15Z