← לוח פגיעויות

CVE-2026-4053

בינונית 4.3

תיאור (מקור, אנגלית)

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631

מדדים

CVSS 3.1
4.3 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-4/8/2026
CWE
CWE-672

מוצרים מושפעים

mattermost: mattermost server

קישורים