Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Desktop App to versions 6.2.0, 5.13.6.0 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Tue, 16 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Desktop
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_desktop:*:-:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost mattermost Desktop
|
Tue, 16 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 15 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651 | |
| Title | Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-06-15T16:00:00.919Z
Reserved: 2026-04-17T14:25:10.246Z
Link: CVE-2026-6517
Updated: 2026-06-15T15:59:52.206Z
Status : Analyzed
Published: 2026-06-15T14:16:37.910
Modified: 2026-06-16T16:54:47.653
Link: CVE-2026-6517
No data.
OpenCVE Enrichment
Updated: 2026-06-18T01:30:15Z