Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Desktop App to versions 6.3.0, 6.2.3.0 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID: MMSA-2026-00717 | |
| Title | Mattermost Desktop App plugin popout scheme validation bypass | |
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-09-17T19:22:50.101Z
Reserved: 2026-08-17T22:19:32.227Z
Link: CVE-2026-75588
Updated: 2026-09-17T19:22:40.335Z
Status : Received
Published: 2026-09-17T16:17:41.940
Modified: 2026-09-17T20:18:14.713
Link: CVE-2026-75588
No data.
OpenCVE Enrichment
Updated: 2026-09-17T21:00:17Z
