CVE-2025-10871 — Missing Authorization in Gitlab
Severity
7.2HIGHNVD
EPSS
0.0%
top 95.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 26
Description
An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-9396-6m54-w269: An issue has been discovered in GitLab EE affecting all versions from 16↗2025-09-26
📋Vendor Advisories
2GitLab▶
CVE-2025-10871: An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintain↗2025-09-26
Debian▶
CVE-2025-10871: gitlab - An issue has been discovered in GitLab EE affecting all versions from 16.6 befor...↗2025