CVE-2026-75587 - Plaintext pre-auth secret exposure via Desktop App diagnostics report
CVE ID :CVE-2026-75587
Published : Aug. 17, 2026, 11:16 p.m. | 1 hour, 20 minutes ago
Description :Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
Severity: 3.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 17, 2026, 11:16 p.m. | 1 hour, 20 minutes ago
Description :Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
Severity: 3.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...