Количество 3
Количество 3
CVE-2026-3637
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026-00627
CVE-2026-3637
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 1 ...
GHSA-v549-xx3c-6pc8
Mattermost doesn't check the create_post channel permission during post edit operations
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-3637 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026-00627 | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-3637 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 1 ... | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-v549-xx3c-6pc8 Mattermost doesn't check the create_post channel permission during post edit operations | CVSS3: 4.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу