CVE-2025-24866
published 2025-04-10CVE-2025-24866: Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular…
PriorityP412low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.28%
20.0th percentile
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 9.11.0+incompatible < 9.11.9+incompatible | 9.11.9+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20250204211032-f52e08754c49 | 8.0.0-20250204211032-f52e08754c49 |
| github.com | mattermost_mattermost_server_v8 | >= 9.11.0 < 9.11.9 | 9.11.9 |
| mattermost | mattermost | 9.11.0 – 9.11.8 | — |
| mattermost | mattermost_server | >= 9.11.0 < 9.11.9 | 9.11.9 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server
osv·2025-04-22
CVE-2025-24866 Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server
GHSA
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
ghsa·2025-04-10
CVE-2025-24866 [LOW] CWE-863 Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
OSV
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
osv·2025-04-10
CVE-2025-24866 [LOW] Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-10
Published