Improper Post Editing Permissions in Mattermost Software
CVE-2026-4053

3.1LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
15 May 2026

What is CVE-2026-4053?

Certain versions of Mattermost fail to enforce the PostEditTimeLimit on non-message post fields, allowing authenticated users to manipulate post file attachments, properties, and pin status even after the designated edit period has passed. This vulnerability can be exploited via the post patch and update API endpoints, leading to unauthorized modifications. For detailed information, refer to the vendor advisory: MMSA-2026-00631.

Affected Version(s)

Mattermost 11.5.0 <= 11.5.1

Mattermost 10.11.0 <= 10.11.13

Mattermost 11.6.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

se1en
.