CVE-2026-9602: Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost Advisory ID: MMSA-2026-00678
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 6.3.0 - Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 6.2.1.0 - Upgrade
Upgrade
Mattermost Desktop Appto a version that resolves this vulnerability.Fixed in 5.13.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9602?
CVE-2026-9602 has a medium severity rating of 5.7.
How do I fix CVE-2026-9602?
To fix CVE-2026-9602, upgrade to a version of the Mattermost Desktop App that is higher than 6.2.
What versions are affected by CVE-2026-9602?
CVE-2026-9602 affects Mattermost Desktop App versions 6.2, 6.0.2, and 5.6.13.0 and earlier.
What kind of attack does CVE-2026-9602 allow?
CVE-2026-9602 allows a malicious server owner to crash the Mattermost Desktop App by sending malformed payloads through exposed IPC methods.
Is CVE-2026-9602 related to any specific platform or software?
CVE-2026-9602 is specifically related to the Mattermost Desktop App.