MEDIUM
post edit time limit is not enforced on some post update operations
Published May 15, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.27%
Description
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631
Affected products
-
- Version 10.11.0StatusaffectedConstraints<=10.11.13
- Version 11.5.0StatusaffectedConstraints<=11.5.1
- Version 10.11.14StatusunaffectedConstraints-
- Version 11.5.2StatusunaffectedConstraints-
- Version 11.6.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mattermost | Mattermost | unaffected |
|
OR
- ≥ 10.11.0 · < 10.11.14
- ≥ 11.5.0 · < 11.5.2
No data.
No Red Hat product state for this CVE.
github.com/mattermost/mattermost-server
Go
Introduced 0.0.0-20250731163400-5b955468ea1e Fixed 0.0.0-20260414103857-b21ef302025egithub.com/mattermost/mattermost-server
Go
Introduced 11.5.0+incompatible Fixed 11.5.2+incompatible
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/mattermost/mattermost-server | 0.0.0-20250731163400-5b955468ea1e | 0.0.0-20260414103857-b21ef302025e |
| Go | github.com/mattermost/mattermost-server | 11.5.0+incompatible | 11.5.2+incompatible |
Remediation
Vendor solution
Update Mattermost to versions 11.6.0, 11.5.2, 10.11.14 or higher.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30586 Advisory
- https://github.com/advisories/GHSA-hw87-6jcq-9f8q Advisory
- https://mattermost.com/security-updates vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-4053
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30586 | Advisory | |
| https://github.com/advisories/GHSA-hw87-6jcq-9f8q | Advisory | |
| https://mattermost.com/security-updates | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-4053 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published May 15, 2026
Updated May 15, 2026
Reserved Mar 12, 2026
Link CVE-2026-4053
CISA Vulnrichment
Updated May 15, 2026
ENISA EUVD
EUVD-2026-30586 GHSA-HW87-6JCQ-9F8Q Assigner Mattermost
Published May 15, 2026
Updated May 15, 2026
Exploited since n/a
Link EUVD-2026-30586