Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026-00627
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
19 May 2026, 17:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://mattermost.com/security-updates - Vendor Advisory | |
| First Time |
Mattermost mattermost Server
Mattermost |
|
| CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
18 May 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-18 08:16
Updated : 2026-05-19 17:34
NVD link : CVE-2026-3637
Mitre link : CVE-2026-3637
CVE.ORG link : CVE-2026-3637
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-862
Missing Authorization
