3.3
CVE-2025-9486
- EPSS 0.23%
- Veröffentlicht 12.08.2026 19:05:46
- Zuletzt bearbeitet 29.09.2026 10:10:00
- Erkennungen
Incorrect Privilege Assignment in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.133 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@gitlab.com | 3.3 | 0.7 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/
https://gitlab.com/gitlab-org/gitlab/-/issues/565412
https://hackerone.com/reports/3262844