CVE-2026-4053
3.1 LOWMattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows a...
Published: 2026-05-15 · Last updated: 2026-05-18
Severity and scoring
- CVSS
- 3.1 LOW
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- CWE
- CWE-672
Affected products
| Vendor | Product |
|---|---|
| mattermost | mattermost_server |
Description
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-4053
- [Vendor advisory]https://mattermost.com/security-updates
Related CVEs
Same vendor
- CVE-2026-6957 — Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destin... (8.0 HIGH)
- CVE-2026-4915 — Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing w... (6.5 MEDIUM)
- CVE-2026-4858 — Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path trav... (8.0 HIGH)
- CVE-2026-4055 — Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook r... (4.3 MEDIUM)
- CVE-2026-6347 — Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Matter... (7.6 HIGH)
Same CWE
- CVE-2026-2379 — On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected beha... (5.9 MEDIUM)
- CVE-2026-33463 — Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure (5.3 MEDIUM)
- CVE-2026-42791 — Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an e... (3.7 LOW)
- CVE-2026-33278 — NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service a... (9.8 CRITICAL)
- CVE-2026-32244 — Discourse is an open-source discussion platform (5.3 MEDIUM)