CVE-2026-2476
published 2026-03-16CVE-2026-2476: Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.18%
7.7th percentile
Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-plugin-msteams | >= 0 < 1.15.1-0.20260102165339-036c761bd3cb | 1.15.1-0.20260102165339-036c761bd3cb |
| mattermost | mattermost | <= 2.0.3 | — |
| mattermost | ms_teams | < 2.3.1 | 2.3.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values in github.com/mattermost/mattermost-plugin-msteams
osv·2026-03-23
CVE-2026-2476 Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values in github.com/mattermost/mattermost-plugin-msteams
Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values in github.com/mattermost/mattermost-plugin-msteams
Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values in github.com/mattermost/mattermost-plugin-msteams
OSV
Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values
osv·2026-03-16
CVE-2026-2476 [HIGH] Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values
Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values
Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
GHSA
Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values
ghsa·2026-03-16
CVE-2026-2476 [HIGH] CWE-200 Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values
Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values
Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
No detection rules found.
No public exploits indexed.
2026-03-16
Published