CVE-2026-3637
published 2026-05-18CVE-2026-3637: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.15%
4.8th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026-00627
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20260316171743-090408f09f53 | 5.3.2-0.20260316171743-090408f09f53 |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20260316171743-090408f09f53 | 8.0.0-20260316171743-090408f09f53 |
| github.com | mattermost_mattermost_server_v8 | >= 10.11.0 < 10.11.14 | 10.11.14 |
| github.com | mattermost_mattermost_server_v8 | >= 11.4.0 < 11.4.4 | 11.4.4 |
| github.com | mattermost_mattermost_server_v8 | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.4.0 – 11.4.3 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.4.0 < 11.4.4 | 11.4.4 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost doesn't check the create_post channel permission during post edit operations
ghsa·2026-05-18
CVE-2026-3637 [MEDIUM] CWE-862 Mattermost doesn't check the create_post channel permission during post edit operations
Mattermost doesn't check the create_post channel permission during post edit operations
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026-00627
VulDB
Mattermost up to 10.11.13/11.4.3/11.5.1 API create_post authorization
vuldb·2026-05-18·CVSS 4.3
CVE-2026-3637 [MEDIUM] Mattermost up to 10.11.13/11.4.3/11.5.1 API create_post authorization
A vulnerability categorized as problematic has been discovered in Mattermost up to 10.11.13/11.4.3/11.5.1. Affected by this issue is the function create_post of the component API. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-3637. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
GHSA-v549-xx3c-6pc8: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-3637 [MEDIUM] CWE-862 GHSA-v549-xx3c-6pc8: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026-00627
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published