Executive brief
Mattermost is a collaboration platform used for team communication and incident response. A vulnerability in the platform's message editing system allows users to modify certain parts of a post, such as file attachments and pinned status, even after the configured time limit for editing has passed. This could allow a user to retroactively alter the context or metadata of a conversation, potentially impacting the integrity of historical records or audit trails.
Technical details
Mattermost Server versions 11.5.x <= 11.5.1 and 10.11.x <= 10.11.13 contain a logic flaw where the 'PostEditTimeLimit' configuration is only applied to the message body of a post. An authenticated attacker can bypass this restriction by targeting the post patch and update API endpoints to modify non-message fields, including file attachments, props, and pin status, after the expiration of the allowed editing window. This is classified as CWE-672 (Operation on a Resource after Expiration or Release). The vulnerability is addressed in Mattermost Server version 11.5.2 and 10.11.14.
Affected products
- Mattermost Mattermost Server 10.11.0 to 10.11.13, 11.5.0 to 11.5.1
Timeline
- 2026-05-15: disclosed
- 2026-05-15: advisory
- 2026-05-28: patched