8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Description
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access to a support packet to obtain sensitive credentials in plaintext via downloading a support packet from the System Console.. Mattermost Advisory ID: MMSA-2026-00607
AI Analysis
Sensitive credentials exposed in plaintext in Mattermost support packets due to insufficient sanitization of configuration fields
Basic Information
ID
CVE-2026-6346
Source
Mattermost
Published
May 18, 2026 at 08:37
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
11.5.0
Affected Versions
Mattermost Mattermost 11.5.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 11.4.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 11.4.0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Mattermost
Product
Mattermost
Version
11.5.0, 10.11.0, 11.4.0