CVE-2026-6517: Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 6.2.0Patch MMSA-2026-00651 - Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 5.13.6.0Patch MMSA-2026-00651
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6517?
CVE-2026-6517 has a medium severity rating of 6.3.
How do I fix CVE-2026-6517?
To mitigate CVE-2026-6517, upgrade to the latest version of Mattermost Desktop App where the issue is resolved.
What are the potential risks associated with CVE-2026-6517?
The risks involve unauthorized interception of NTLM credentials by users on servers without image proxy enabled.
Which versions of Mattermost Desktop App are affected by CVE-2026-6517?
Mattermost Desktop App versions 6.1 and 5.5.13.0 are affected by CVE-2026-6517.
Is user interaction required to exploit CVE-2026-6517?
No, user interaction is not required to exploit CVE-2026-6517.