Junglewise Threat Intelligence

CVE-2026-6339: Mattermost origin validation error in burn-on-read reveal endpoint

CVE-2026-6339 · Severity: medium · CVSS 4.3 · Published 2026-05-18

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), Mattermost Server, github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go, Mattermost.

Executive brief

Mattermost is a collaboration platform used for secure team communication. A vulnerability in the 'burn-on-read' feature allows an authorized user to force a message to be revealed and subsequently deleted without the intended recipient's consent. This could be used to disrupt communications or prematurely destroy sensitive information by tricking the system into thinking the message has already been read.

Technical details

An origin validation error (CWE-346) exists in Mattermost Server's 'burn-on-read' (BoR) reveal endpoint. The application fails to verify the presence or validity of the X-Requested-With header, which is typically used to prevent cross-site request forgery and unauthorized automated interactions. An authenticated channel member can exploit this by embedding a crafted Markdown image tag in a post; when a recipient's client attempts to render the image, it triggers the reveal endpoint. This results in the message being 'burned' (deleted) without the recipient actually viewing the content. Patches are available in versions 11.5.2, 11.4.4, and specific backported builds.

Affected products

  • Mattermost Mattermost Server 11.5.0 - 11.5.1, 11.4.0 - 11.4.3, < 8.0.0-20260327001745-7a339a6438f5

Timeline

  • 2026-05-18: disclosed
  • 2026-05-18: advisory
  • 2026-06-01: patched: GitHub advisory reviewed and updated with patch details.

References

Related threats