CVE-2026-6346: Sensitive credentials exposed in plaintext in Mattermost support packets
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access to a support packet to obtain sensitive credentials in plaintext via downloading a support packet from the System Console.. Mattermost Advisory ID: MMSA-2026-00607
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.14 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.4.4 - Operational
If any support packets were downloaded before upgrading, rotate any sensitive credentials that may have been exposed in plaintext within Mattermost support packets (per MMSA-2026-00607).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6346?
CVE-2026-6346 has been categorized as a high-severity vulnerability due to the exposure of sensitive credentials.
Which Mattermost versions are affected by CVE-2026-6346?
CVE-2026-6346 affects Mattermost versions 11.5.x up to 11.5.1, 10.11.x up to 10.11.13, and 11.4.x up to 11.4.3.
How do I fix CVE-2026-6346?
To fix CVE-2026-6346, upgrade Mattermost to a version that is not affected, specifically later than the mentioned vulnerable versions.
What types of sensitive information are exposed in CVE-2026-6346?
CVE-2026-6346 exposes sensitive configuration fields, including credentials, in plaintext within support packets.
Can a non-administrator exploit CVE-2026-6346?
Yes, any party with access to a support packet can exploit CVE-2026-6346 to access sensitive information, not just Mattermost System Admins.