CVE-2026-4053
published 2026-05-15CVE-2026-4053: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.17%
6.1th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0.0.0-20250731163400-5b955468ea1e < 0.0.0-20260414103857-b21ef302025e | 0.0.0-20260414103857-b21ef302025e |
| github.com | mattermost_mattermost-server | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mattermost up to 10.11.13/11.5.1/11.5.x API Endpoint operation after expiration
vuldb·2026-05-16·CVSS 3.1
CVE-2026-4053 [LOW] Mattermost up to 10.11.13/11.5.1/11.5.x API Endpoint operation after expiration
A vulnerability classified as problematic was found in Mattermost up to 10.11.13/11.5.1/11.5.x. Affected is an unknown function of the component API Endpoint. The manipulation results in operation on a resource after expiration.
This vulnerability was named CVE-2026-4053. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
GHSA
GHSA-hw87-6jcq-9f8q: Mattermost versions 11
ghsa_unreviewed·2026-05-15
CVE-2026-4053 [LOW] CWE-672 GHSA-hw87-6jcq-9f8q: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631
GHSA
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields
ghsa·2026-05-15
CVE-2026-4053 [LOW] CWE-672 Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints. Mattermost Advisory ID: MMSA-2026-00631.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-15
Published