CVE-2026-6339: Missing request origin validation on burn-on-read reveal endpoint
Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image tag.. Mattermost Advisory ID: MMSA-2026-00636
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6339?
CVE-2026-6339 has a medium severity level due to the potential for unauthorized message reveals by authenticated users.
How do I fix CVE-2026-6339?
To fix CVE-2026-6339, update Mattermost to version 11.5.2 or higher, or 11.4.4 or higher to ensure proper request origin validation.
What types of Mattermost versions are affected by CVE-2026-6339?
Mattermost versions 11.5.x up to 11.5.1 and 11.4.x up to 11.4.3 are affected by CVE-2026-6339.
What is the impact of CVE-2026-6339?
The impact of CVE-2026-6339 allows authenticated channel members to potentially reveal burn-on-read messages that should remain concealed.
Is user authentication required to exploit CVE-2026-6339?
Yes, user authentication is required to exploit CVE-2026-6339, as it involves authenticated channel members.