Mattermost · Mattermost Desktop App · CVE-2026-9602
**Name of the Vulnerable Software and Affected Versions**
Mattermost Desktop App versions prior to 6.2
Mattermost Desktop App version 6.0.2
Mattermost Desktop App version 5.6.13.0
**Description**
The application fails to validate payloads sent from the Mattermost Web App to the Desktop App. This allows a malicious server owner to crash the Desktop App by modifying a method payload to be malformed.
**Recommendations**
Update Mattermost Desktop App to a version newer than 6.2.
Update Mattermost Desktop App to a version newer than 6.0.2.
Update Mattermost Desktop App to a version newer than 5.6.13.0.