CVE-2026-1046: Mattermost Desktop
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
Affected products
- Mattermost Mattermost Desktop: from 5.13.2, before 5.13.3 (fixed in 5.13.3); from 6.0.0, before 6.0.3 (fixed in 6.0.3)
Published 2026-02-16. Last modified 2026-06-17.