CVE-2026-2476: MS Teams plugin sensitive config values not properly masked in support packets
Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2476?
CVE-2026-2476 has been classified as a high severity vulnerability due to the exposure of sensitive configuration values in Mattermost Plugins.
How do I fix CVE-2026-2476?
To address CVE-2026-2476, upgrade to Mattermost Plugins version 2.0.3.1 or later to ensure proper masking of sensitive configuration values.
What are the potential impacts of CVE-2026-2476?
The potential impact of CVE-2026-2476 includes unauthorized access to sensitive configuration details that could lead to further exploitation or data breaches.
Which versions of Mattermost Plugins are affected by CVE-2026-2476?
CVE-2026-2476 affects all Mattermost Plugins versions up to and including 2.0.3.0.
Who can exploit CVE-2026-2476?
An attacker with access to support packets can exploit CVE-2026-2476 to retrieve original plugin settings that should be secure.