CVE-2024-24776: Mattermost Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.
Affected products
- Mattermost Mattermost Server: up to and including 8.1.7
Published 2024-02-09. Last modified 2026-06-17.