---
id: CVE-2026-12284
title: >-
  Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender
  in the leaveCall handler which allows a malicious or compromised Mattermost
  server (or a user with script access to a connected server view) to disconnect
  an …
summary: >-
  Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender
  in the leaveCall handler which allows a malicious or compromised Mattermost
  server (or a user with script access to a connected server view) to disconnect
  an …
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-346
vendor: Mattermost
product: Mattermost
affected:
  - Mattermost <= 6.2.2
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:46:33.503'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12284'
references:
  - url: 'https://mattermost.com/security-updates'
    label: responsibledisclosure@mattermost.com
tags:
  - nvd
  - cve.org
epss: 0.00131
epssPercentile: 0.02249
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:18:33.462460Z'
scores:
  nvd: 3.7
  cna: 3.8
ingestedAt: '2026-09-17T16:21:47.707Z'
---

## Overview

Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall IPC message. Mattermost Advisory ID: MMSA-2026-00699

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
