CVE-2026-6339
published 2026-05-18CVE-2026-6339: Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.11%
1.6th percentile
Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image tag.. Mattermost Advisory ID: MMSA-2026-00636
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20260327001745-7a339a6438f5 | 5.3.2-0.20260327001745-7a339a6438f5 |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20260327001745-7a339a6438f5 | 8.0.0-20260327001745-7a339a6438f5 |
| github.com | mattermost_mattermost_server_v8 | >= 11.4.0 < 11.4.4 | 11.4.4 |
| github.com | mattermost_mattermost_server_v8 | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 11.4.0 – 11.4.3 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 11.4.0 < 11.4.4 | 11.4.4 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
ghsa·2026-05-18
CVE-2026-6339 [MEDIUM] CWE-346 Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image tag.. Mattermost Advisory ID: MMSA-2026-00636
GHSA
GHSA-xvcx-mgpc-5xh3: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-6339 [MEDIUM] CWE-346 GHSA-xvcx-mgpc-5xh3: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image tag.. Mattermost Advisory ID: MMSA-2026-00636
VulDB
Mattermost up to 11.4.3/11.5.1 Markdown origin validation (EUVD-2026-30749)
vuldb·2026-05-18·CVSS 4.3
CVE-2026-6339 [MEDIUM] Mattermost up to 11.4.3/11.5.1 Markdown origin validation (EUVD-2026-30749)
A vulnerability was found in Mattermost up to 11.4.3/11.5.1. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Markdown Handler. This manipulation causes origin validation error.
This vulnerability appears as CVE-2026-6339. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published