CVE-2026-6347: Mattermost Calls plugin exposes TURN server credentials in plaintext in support packets
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server credentials via the plaintext values present in the exported plugin configuration.. Mattermost Advisory ID: MMSA-2026-00605
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Calls plugin (MMSA-2026-00605)to a version that resolves this vulnerability.Fixed in 11.6.0 - Upgrade
Upgrade
Mattermost Calls plugin (MMSA-2026-00605)to a version that resolves this vulnerability.Fixed in 11.5.2 - Upgrade
Upgrade
Mattermost Calls plugin (MMSA-2026-00605)to a version that resolves this vulnerability.Fixed in 10.11.14 - Upgrade
Upgrade
Mattermost Calls plugin (MMSA-2026-00605)to a version that resolves this vulnerability.Fixed in 11.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6347?
The severity of CVE-2026-6347 is classified as high due to the exposure of sensitive TURN server credentials in plaintext.
How do I fix CVE-2026-6347?
To fix CVE-2026-6347, upgrade to Mattermost versions 11.5.2, 10.11.14, or 11.4.4 or later.
What versions of Mattermost are affected by CVE-2026-6347?
Mattermost versions 11.5.0 to 11.5.1, 10.11.0 to 10.11.13, and 11.4.0 to 11.4.3 are affected by CVE-2026-6347.
What are the implications of CVE-2026-6347?
CVE-2026-6347 may allow unauthorized users to obtain TURN server credentials, leading to potential security breaches.
Is there a workaround for CVE-2026-6347?
There is no official workaround for CVE-2026-6347; users are advised to update to the patched versions as soon as possible.