Beveiligingsadvies

CVE-2026-6517

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-15 13:55:25
Laatst bijgewerkt 2026-06-15 16:00:00
Toegewezen door Mattermost
CVSS-score 6.3
Status PUBLISHED

Beschrijving

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651