CVE-2026-1046
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:L
- EPSS probability
- 0.24%
- CWE
- CWE-939
- Published
- 2026-02-16
- Last modified
- 2026-03-12
Affected products
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
Weakness type
Related vulnerabilities
- CVE-2026-73335 — Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL...
- CVE-2026-59717 — Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing
- CVE-2026-12190 — Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme
- CVE-2026-12189 — Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
- CVE-2026-53408 — Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for...
- CVE-2026-53407 — Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for...
- CVE-2026-12065 — Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
- CVE-2026-6445 — A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose...