CVE-2025-24866

Mattermost versions 9.11.x <= 9.11.8  fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

01 Oct 2025, 18:06

Type Values Removed Values Added
First Time Mattermost
Mattermost mattermost Server
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

11 Apr 2025, 15:39

Type Values Removed Values Added
Summary
  • (es) Las versiones 9.11.x &lt;= 9.11.8 de Mattermost no implementan controles de acceso adecuados en el endpoint /api/v4/audits, lo que permite que los usuarios con roles de administración granular delegados que no tienen acceso a la Supervisión de cumplimiento recuperen registros de actividad del usuario.

10 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-10 16:15

Updated : 2025-10-01 18:06


NVD link : CVE-2025-24866

Mitre link : CVE-2025-24866

CVE.ORG link : CVE-2025-24866


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-863

Incorrect Authorization