CyberRota Analysis
AI-GeneratedThe Mattermost Desktop App versions up to 6.2.2.0 expose a pre-authentication secret in diagnostics reports, which can be accessed by local attackers with access to these reports or log files. This vulnerability could lead to unauthorized access to connected servers if the plaintext secret is compromised. Organizations using affected versions should prioritize remediation to prevent potential local attacks.
Original NVD Description
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
Related CVEs
Other vulnerabilities affecting the same vendor(s)