CVE-2025-11246
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from…
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1220
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/Release Notes, Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/573728Broken Link
- https://hackerone.com/reports/3292475Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.