CVE-2025-9486
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a…
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/Release Notes
- https://gitlab.com/gitlab-org/gitlab/-/issues/565412Broken Link
- https://hackerone.com/reports/3262844Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.