PT-2026-49238 · Mattermost · Mattermost Desktop App

·

CVE-2026-6517

·

Published

2026-06-15

·

Updated

2026-06-16

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Desktop App versions prior to 6.1 Mattermost Desktop App version 5.5.13.0
Description The application fails to restrict the allow list of domains for NTLM credential forwarding. This allows a user on a server where the image proxy is disabled to intercept other users' credentials by embedding an image that routes to an external web server. NTLM (NT LAN Manager) is a suite of security protocols used to authenticate users.
Recommendations Update Mattermost Desktop App to a version later than 6.1. Update Mattermost Desktop App to a version later than 5.5.13.0. Enable the image proxy on the server to prevent the interception of credentials via embedded images.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6517

Affected Products

Mattermost Desktop App