CVE-2026-4053

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631

Scoring

Severity
LOW
CVSS base score
3.1
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS probability
0.17%
CWE
CWE-672
Published
2026-05-15
Last modified
2026-05-15

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs