Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update Mattermost to versions 11.6.0, 11.5.2, 10.11.14 or higher.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 15 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631 | |
| Title | post edit time limit is not enforced on some post update operations | |
| Weaknesses | CWE-672 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-05-15T20:01:17.492Z
Reserved: 2026-03-12T16:07:22.695Z
Link: CVE-2026-4053
No data.
Status : Received
Published: 2026-05-15T19:17:04.670
Modified: 2026-05-15T19:17:04.670
Link: CVE-2026-4053
No data.
OpenCVE Enrichment
Updated: 2026-05-15T20:30:06Z
Weaknesses