Impact
Mattermost does not enforce the create_post channel permission when users edit existing posts. An attacker who has been authenticated to the system but whose posting rights have been revoked can still alter the content of their own posts by sending API requests to the post update and patch endpoints. This flaw is a Missing Authorization weakness (CWE-862) that compromises the integrity of user‑generated content.
Affected Systems
The vulnerability affects Mattermost versions 11.5.x through 11.5.1, 10.11.x through 10.11.13, and 11.4.x through 11.4.3. Updated releases 11.6.0, 11.5.2, 10.11.14, 11.4.4 and later address the issue.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Successful exploitation requires authentication and the ability to send API requests; once achieved, the attacker can modify post content that was previously restricted, representing a moderate risk to data integrity.
OpenCVE Enrichment