CVE-2026-2578: Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts
Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2578?
CVE-2026-2578 is classified as a medium-severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2026-2578?
To fix CVE-2026-2578, upgrade Mattermost to version 11.3.1 or later, as this version addresses the issue.
What type of vulnerability is CVE-2026-2578?
CVE-2026-2578 is an information disclosure vulnerability that affects the handling of burn-on-read posts in Mattermost.
Who is affected by CVE-2026-2578?
Users of Mattermost versions 11.3.x up to and including 11.3.0 are affected by CVE-2026-2578.
What can attackers gain from exploiting CVE-2026-2578?
Attackers can gain access to unrevealed content of burn-on-read messages that should be redacted upon deletion.