---
id: CVE-2024-25169
aliases:
  - GHSA-qp56-82vp-xqgv
  - PYSEC-2026-1627
title: Mezzanine allows attackers to bypass access control mechanisms
summary: Mezzanine allows attackers to bypass access control mechanisms
severity: medium
vendor: mezzanine
product: mezzanine
ecosystem: pip
affected:
  - mezzanine <= 6.0.0
published: '2024-02-28'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-qp56-82vp-xqgv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-25169'
  - url: 'https://github.com/shenhav12/CVE-2024-25169-Mezzanine-v6.0.0'
  - url: 'https://github.com/stephenmcd/mezzanine'
  - url: 'https://ibb.co/JKh4hmD'
  - url: 'https://ibb.co/Pt9qd8t'
  - url: 'https://ibb.co/hLLPTVp'
  - url: 'https://ibb.co/rfrKj3r'
tags:
  - osv
  - pip
  - exploit-available
epss: 0.01105
epssPercentile: 0.64365
ingestedAt: '2026-07-08T18:25:52.462Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/shenhav12/CVE-2024-25169-Mezzanine-v6.0.0'
  checkedAt: '2026-09-26T09:05:31.000Z'
exploitAvailable: true
---

## Overview

An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.

## Affected packages

- `mezzanine <= 6.0.0`

## Remediation

Refer to the advisory for the patched release.
