Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631
Advisories
No advisories yet.
Fixes
Solution
Update Mattermost to versions 11.6.0, 11.5.2, 10.11.14 or higher.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 15 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Fri, 15 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631 | |
| Title | post edit time limit is not enforced on some post update operations | |
| Weaknesses | CWE-672 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-05-15T20:01:17.492Z
Reserved: 2026-03-12T16:07:22.695Z
Link: CVE-2026-4053
No data.
Status : Received
Published: 2026-05-15T19:17:04.670
Modified: 2026-05-15T19:17:04.670
Link: CVE-2026-4053
No data.
OpenCVE Enrichment
Updated: 2026-05-15T21:00:08Z
Weaknesses