← Back to CVEs
CVE-2026-1046
HIGH7.6
Description
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
CVE Details
CVSS v3.1 Score7.6
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:L
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
Published2/16/2026
Last Modified3/23/2026
Sourcenvd
Honeypot Sightings0
Affected Products
mattermost:mattermost_desktop
Weaknesses (CWE)
CWE-939
References
https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.