
Cloud Vulnerability DB
A community-led vulnerabilities database
Mattermost versions 9.11.x <= 9.11.8 contain an incorrect authorization vulnerability (CVE-2025-24866) that fails to enforce proper access controls on the /api/v4/audits endpoint. This allows users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 2.7 (LOW) with the following vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N. The issue is classified as CWE-863 (Incorrect Authorization) and affects the access control mechanism for the /api/v4/audits endpoint (NVD).
When exploited, this vulnerability allows users with delegated granular administration roles to access User Activity Logs through the /api/v4/audits endpoint, despite not having the required Compliance Monitoring permissions (NVD).
The vulnerability requires high privileges (delegated granular administration roles) to exploit, but has low attack complexity and requires no user interaction. The attack vector is network-accessible (NVD).
Users should upgrade to a version higher than Mattermost 9.11.8 to address this vulnerability (Mattermost Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."