Junglewise Threat Intelligence

CVE-2026-6346: Mattermost sensitive information disclosure in support packet generation

CVE-2026-6346 · Severity: high · CVSS 8.7 · Published 2026-05-18

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), Mattermost Server, github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go, Mattermost.

Executive brief

Mattermost, a popular collaboration and messaging platform, contains a vulnerability where sensitive configuration data is not properly hidden when generating support diagnostic files. This could allow a system administrator or anyone with access to these support files to view sensitive credentials, such as passwords or API keys, in plain text. Exposure of these credentials could lead to unauthorized access to other integrated corporate systems or the underlying database.

Technical details

A sensitive information disclosure vulnerability (CWE-200) exists in Mattermost Server due to improper sanitization of configuration fields during the generation of support packets. When a System Administrator generates a support packet via the System Console, the resulting file includes sensitive credentials in plaintext rather than masked or redacted values. An attacker with System Admin privileges, or an unauthorized party who gains access to a downloaded support packet, can extract these credentials to compromise connected services. The vulnerability is addressed by implementing 'FakeSetting' logic to mask sensitive keys during the packet generation process. Patches are available in versions 11.5.2, 11.4.4, and 10.11.14.

Affected products

  • Mattermost Mattermost Server 11.5.0 - 11.5.1, 11.4.0 - 11.4.3, 10.11.0 - 10.11.13, < 8.0.0-20260326202606-fac92f4a71f3

Timeline

  • 2026-05-18: disclosed
  • 2026-05-18: advisory
  • 2026-06-01: other: Advisory reviewed and updated

References

Related threats