Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9699

Опубликовано: 26 июн. 2026
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during authentication failures. Mattermost Advisory ID: MMSA-2026-00609

EPSS

Процентиль: 24%
0.00325
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.8
github
около 1 месяца назад

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during authentication failures. Mattermost Advisory ID: MMSA-2026-00609

EPSS

Процентиль: 24%
0.00325
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-532