← back
CVE-2026-6347highCWE-200

Mattermost Calls plugin exposes TURN server credentials in plaintext in support packets

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.6epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server credentials via the plaintext values present in the exported plugin configuration.. Mattermost Advisory ID: MMSA-2026-00605
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Affected products
Mattermost · Mattermost