CVE-2026-1046: Arbitrary application execution via unvalidated server-controlled URLs in Help menu
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1046?
CVE-2026-1046 is considered to have a high severity due to its potential for arbitrary code execution on user systems.
How do I fix CVE-2026-1046?
To mitigate CVE-2026-1046, update the Mattermost Desktop App to a version newer than 6.2.0.
Who is affected by CVE-2026-1046?
Users of Mattermost Desktop App versions 5.2.13.0, 6.0, and 6.2.0 are affected by CVE-2026-1046.
What type of vulnerability is CVE-2026-1046?
CVE-2026-1046 is an arbitrary code execution vulnerability caused by unvalidated server-controlled URLs.
How can attackers exploit CVE-2026-1046?
Attackers can exploit CVE-2026-1046 by crafting malicious help links that execute arbitrary executables on a user's system.