Junglewise Threat Intelligence

CVE-2026-9602: Mattermost Desktop App denial of service via malformed payload

CVE-2026-9602 · Severity: medium · CVSS 6.5 · Published 2026-07-17

Executive brief

A vulnerability in the Mattermost Desktop App allows a malicious server owner to crash the application on a user's computer. This occurs because the desktop software does not properly check the data it receives from the web server. An exploit would result in a denial of service, preventing employees from using the communication platform until the application is restarted or patched.

Technical details

The Mattermost Desktop App suffers from an uncontrolled resource consumption vulnerability (CWE-400) due to insufficient validation of payloads sent from the Mattermost Web App. A malicious server administrator can send a malformed method payload to the client application, triggering a crash. This is a network-based attack requiring low privileges (server owner status) but no user interaction. The vulnerability is addressed in versions 6.3.0, 6.2.1.0, and 5.13.7.0.

Affected products

  • Mattermost Desktop App <=6.2, 6.0.2, 5.6.13.0

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References

Related threats