CVE-2025-7691 — Privilege Defined With Unsafe Actions in Gitlab
Severity
8.8HIGHNVD
EPSS
0.0%
top 99.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 26
Description
A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-38q5-vqf6-27rf: A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16↗2025-09-26
📋Vendor Advisories
2GitLab▶
CVE-2025-7691: A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior t↗2025-09-26
Debian▶
CVE-2025-7691: gitlab - A privilege escalation issue has been discovered in GitLab EE affecting all vers...↗2025