First published: Thu Apr 10 2025(Updated: )
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <=9.11.8 | |
go/github.com/mattermost/mattermost/server/v8 | >=9.11.0<9.11.9 | 9.11.9 |
go/github.com/mattermost/mattermost/server/v8 | <8.0.0-20250204211032-f52e08754c49 | 8.0.0-20250204211032-f52e08754c49 |
Update Mattermost to versions 10.5.0, 9.11.9 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24866 has been rated as a critical severity vulnerability due to improper access controls.
To fix CVE-2025-24866, upgrade Mattermost to version 9.11.9 or later to ensure proper access controls are enforced.
CVE-2025-24866 affects Mattermost versions 9.11.x up to and including 9.11.8.
The risks associated with CVE-2025-24866 include unauthorized access to sensitive User Activity Logs by users with insufficient permissions.
There are no official workarounds for CVE-2025-24866; the only mitigation is to upgrade to a patched version.