CVE-2026-75588: Mattermost
Low severity, CVSS 2.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID: MMSA-2026-00717
Affected products
- Mattermost Mattermost: up to and including 6.2.2
Published 2026-09-17. Last modified 2026-09-18.