CVE-2025-24866: Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
(updated )
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-24866 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →