What is CVE-2026-75587?
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret in generated diagnostics reports. This allows a local attacker with access to log files to obtain the plaintext secret configured for a connected server. Updating to the latest version is recommended.
Azərbaycanca: Mattermost Desktop App-in <=6.2 6.2.2.0 versiyaları diaqnostika hesabatı yaradarkən pre-auth sirrini maskalamır. Bu, lokal təcavüzkara istifadəçinin log fayllarından həmin sirri açıq mətn şəklində əldə etməyə imkan verir. Tətbiqi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Mattermost
FAQ2
Which versions of Mattermost Desktop App are affected by CVE-2026-75587?
This vulnerability affects Mattermost Desktop App versions <=6.2 6.2.2.0.
What does CVE-2026-75587 allow a local attacker to do?
The vulnerability allows a local attacker with access to log files to obtain the plaintext pre-auth secret configured for a connected server via diagnostics reports.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.