Executive brief
Mattermost, a popular collaboration and messaging platform, contains a vulnerability in its 'Calls' plugin that fails to properly hide sensitive information. An attacker with administrative access to system support logs (support packets) can view TURN server credentials in plain text. This could allow an unauthorized party to hijack video/audio calling infrastructure or gain deeper access to the communication environment.
Technical details
A sensitive information disclosure vulnerability (CWE-200) exists in the Mattermost Calls plugin due to insufficient sanitization of configuration fields. When a support packet is generated for troubleshooting, the plugin includes the 'ICEServersConfigs' and 'TURNStaticAuthSecret' fields in plaintext within the exported configuration. An attacker with high privileges (sufficient to access or generate support packets) can extract TURN server usernames and passwords. This vulnerability is addressed by marking these configuration keys as 'secret' in the plugin metadata to ensure they are redacted during exports. Patches are available in Mattermost Server versions 11.5.2, 10.11.14, and 11.4.4, and Calls plugin version 1.12.0-rc2.
Affected products
- Mattermost Mattermost Server 11.5.0 - 11.5.1, 10.11.0 - 10.11.13, 11.4.0 - 11.4.3
- Mattermost Mattermost Calls Plugin < 1.12.0-rc2
Timeline
- 2026-05-18: disclosed
- 2026-05-18: advisory
- 2026-06-01: patched