TROYANOSYVIRUS
Retour aux CVEs

CVE-2026-1046

HIGH
7.6

Description

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577

Details CVE

Score CVSS v3.17.6
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:L
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie2/16/2026
Derniere modification3/23/2026
Sourcenvd
Observations honeypot0

Produits affectes

mattermost:mattermost_desktop

Faiblesses (CWE)

CWE-939

References

https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.