Junglewise Threat Intelligence

CVE-2026-4053: Mattermost improper time limit enforcement for post metadata edits

CVE-2026-4053 · Severity: low · CVSS 3.1 · Published 2026-05-15

Technologies: Mattermost Server, github.com/mattermost/mattermost-server (Go). Vendors: Mattermost, Go.

Executive brief

Mattermost is a collaboration platform used for team communication and incident response. A vulnerability in the platform's message editing system allows users to modify certain parts of a post, such as file attachments and pinned status, even after the configured time limit for editing has passed. This could allow a user to retroactively alter the context or metadata of a conversation, potentially impacting the integrity of historical records or audit trails.

Technical details

Mattermost Server versions 11.5.x <= 11.5.1 and 10.11.x <= 10.11.13 contain a logic flaw where the 'PostEditTimeLimit' configuration is only applied to the message body of a post. An authenticated attacker can bypass this restriction by targeting the post patch and update API endpoints to modify non-message fields, including file attachments, props, and pin status, after the expiration of the allowed editing window. This is classified as CWE-672 (Operation on a Resource after Expiration or Release). The vulnerability is addressed in Mattermost Server version 11.5.2 and 10.11.14.

Affected products

  • Mattermost Mattermost Server 10.11.0 to 10.11.13, 11.5.0 to 11.5.1

Timeline

  • 2026-05-15: disclosed
  • 2026-05-15: advisory
  • 2026-05-28: patched

References

Related threats