← Vulnerability feed

Vulnerability record · CVE-2020-14456 · published 19 June 2020

CVE-2020-14456: Mattermost desktop origin validation error vulnerability

Mattermost · Mattermost Desktop

An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.

7.3 CVSS 3.1 High EPSS 0.43% · top 65.7% CWE-346 · Origin validation error
7.3CVSS 3.1 base score, v2 7.5
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-14456 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-11064Mattermost desktop code injection vulnerabilityAn issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.EPSS 1.3%9.8CVE-2019-20856Mattermost desktop uncontrolled search path element vulnerabilityAn issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.EPSS 1.4%8.8CVE-2019-20861Mattermost desktop vulnerabilityAn issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.EPSS 1.7%7.8CVE-2024-39613Mattermost desktop uncontrolled search path element vulnerabilityMattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able t…EPSS 0.30%7.7CVE-2026-6517Mattermost desktop insufficiently protected credentials vulnerabilityMattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermo…EPSS 0.32%6.5CVE-2026-8075Mattermost desktop vulnerabilityMattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows…EPSS 0.42%6.5CVE-2026-9602Mattermost desktop uncontrolled resource consumption vulnerabilityMattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a mal…EPSS 0.42%6.5CVE-2026-8683Mattermost desktop allocation without limits vulnerabilityMattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows …EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2020-14456), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.