Mattermost Desktop App 6.2 Crash via Header Null Bug CVE20268075
CVE-2026-8075 Published on July 17, 2026
Posting a malicious markdown image crashes the Mattermost Desktop App
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image that misses one of those headers. Mattermost Advisory ID: MMSA-2026-00668
Vulnerability Analysis
CVE-2026-8075 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Improper Check for Unusual or Exceptional Conditions
The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.
Products Associated with CVE-2026-8075
Want to know whenever a new CVE is published for MatterMost? stack.watch will email you.
Affected Versions
Mattermost:- Before and including 5.5.13 is affected.
- Before and including 6.0.2 is affected.
- Version 6.3.0 is unaffected.
- Version 5.13.6.0 is unaffected.
- Version 6.2.1.0 is unaffected.