← Vulnerability feed

Vulnerability record · CVE-2026-9602 · published 17 July 2026

CVE-2026-9602: Mattermost desktop uncontrolled resource consumption vulnerability

Mattermost · Mattermost Desktop

Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost Advisory ID: MMSA-2026-00678

6.5 CVSS 3.1 Medium EPSS 0.42% · top 66.2% CWE-400 · Uncontrolled resource consumption
6.5CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
30 Jul 2026Last modified by NVD

Description

Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost Advisory ID: MMSA-2026-00678

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://mattermost.com/security-updates Vendor Advisory

Track CVE-2026-9602 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-11064Mattermost desktop code injection vulnerabilityAn issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.EPSS 1.3%9.8CVE-2019-20856Mattermost desktop uncontrolled search path element vulnerabilityAn issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.EPSS 1.4%8.8CVE-2019-20861Mattermost desktop vulnerabilityAn issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.EPSS 1.7%7.8CVE-2024-39613Mattermost desktop uncontrolled search path element vulnerabilityMattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able t…EPSS 0.30%7.7CVE-2026-6517Mattermost desktop insufficiently protected credentials vulnerabilityMattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermo…EPSS 0.32%7.3CVE-2020-14456Mattermost desktop origin validation error vulnerabilityAn issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, ak…EPSS 0.43%6.5CVE-2026-8075Mattermost desktop vulnerabilityMattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows…EPSS 0.42%6.5CVE-2026-8683Mattermost desktop allocation without limits vulnerabilityMattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows …EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2026-9602), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.