CVE-2025-24866: Unauthorized Access to User Activity Logs API by delegated granular administration roles
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24866?
CVE-2025-24866 has been rated as a critical severity vulnerability due to improper access controls.
How do I fix CVE-2025-24866?
To fix CVE-2025-24866, upgrade Mattermost to version 9.11.9 or later to ensure proper access controls are enforced.
Which versions are affected by CVE-2025-24866?
CVE-2025-24866 affects Mattermost versions 9.11.x up to and including 9.11.8.
What are the risks associated with CVE-2025-24866?
The risks associated with CVE-2025-24866 include unauthorized access to sensitive User Activity Logs by users with insufficient permissions.
Is there a workaround for CVE-2025-24866?
There are no official workarounds for CVE-2025-24866; the only mitigation is to upgrade to a patched version.