Improper Post Editing Permissions in Mattermost Software
CVE-2026-4053
3.1LOW
What is CVE-2026-4053?
Certain versions of Mattermost fail to enforce the PostEditTimeLimit on non-message post fields, allowing authenticated users to manipulate post file attachments, properties, and pin status even after the designated edit period has passed. This vulnerability can be exploited via the post patch and update API endpoints, leading to unauthorized modifications. For detailed information, refer to the vendor advisory: MMSA-2026-00631.
Affected Version(s)
Mattermost 11.5.0 <= 11.5.1
Mattermost 10.11.0 <= 10.11.13
Mattermost 11.6.0