CVE-2026-2476

Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:ms_teams:*:*:*:*:*:mattermost:*:*

History

No history.

Information

Published : 2026-03-16 14:19

Updated : 2026-03-20 18:29


NVD link : CVE-2026-2476

Mitre link : CVE-2026-2476

CVE.ORG link : CVE-2026-2476


JSON object : View

Products Affected

mattermost

  • ms_teams
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo