CVE-2026-9699: Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication errors
Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during authentication failures. Mattermost Advisory ID: MMSA-2026-00609
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Plugins (OpenAI Agents)to a version that resolves this vulnerability.Fixed in 11.7.0 - Upgrade
Upgrade
Mattermost Plugins (OpenAI Agents)to a version that resolves this vulnerability.Fixed in 10.11.19 - Upgrade
Upgrade
Mattermost Plugins (OpenAI Agents)to a version that resolves this vulnerability.Fixed in 11.6.4 - Upgrade
Upgrade
Mattermost Plugins (OpenAI Agents)to a version that resolves this vulnerability.Fixed in 11.5.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9699?
CVE-2026-9699 has a medium severity rating of 6.8.
How do I fix CVE-2026-9699?
To resolve CVE-2026-9699, upgrade to Mattermost Plugins version 11.6.6 or later.
What is the risk associated with CVE-2026-9699?
CVE-2026-9699 has a risk score of 27, indicating a significant potential threat.
What types of information can be exposed by CVE-2026-9699?
CVE-2026-9699 can expose unsanitized OpenAI API keys through error logs.
Which versions of Mattermost Plugins are affected by CVE-2026-9699?
CVE-2026-9699 affects Mattermost Plugins versions 11.6, 10.18.11, 11.3.6, and 11.6.5.0.