Junglewise Threat Intelligence

CVE-2026-9699: Mattermost Plugins sensitive information disclosure in OpenAI logging

CVE-2026-9699 · Severity: medium · CVSS 6.8 · Published 2026-06-26

Technologies: Mattermost Plugins. Vendors: Mattermost.

Executive brief

Mattermost plugins used for AI integration fail to properly hide sensitive credentials when recording system errors. This allows individuals with access to server logs or support diagnostic files to view OpenAI API keys, which could lead to unauthorized use of the organization's AI accounts and associated costs. Organizations should update their Mattermost plugins to the latest versions to ensure these keys are properly masked.

Technical details

A sensitive information disclosure vulnerability (CWE-532) exists in Mattermost Plugins due to insufficient sanitization of OpenAI API error responses. When authentication failures occur, the plugin logs the raw error response from OpenAI into the mattermost.log file or support packets. An attacker with high privileges (PR:H) or access to the server's file system can inspect these logs to recover or reconstruct valid OpenAI API keys. The vulnerability is addressed in versions 11.7.0, 10.11.19, 11.6.4, and 11.5.7.

Affected products

  • Mattermost Mattermost Plugins <= 10.18.11, <= 11.3.6, <= 11.6.5

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References

Related threats