CVE-2026-2725
published 2026-05-13CVE-2026-2725: Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a…
PriorityP432medium5.3CVSS 3.1
AVNACHPRLUINSUCNIHAN
EPSS
0.12%
1.9th percentile
Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gerrit | gerrit | — | — |
| gerrit | >= 2.12 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gerrit: Gerrit: Code review bypass via incorrect authorization
vendor_redhat·2026-05-13·CVSS 6.0
CVE-2026-2725 [MEDIUM] CWE-639 gerrit: Gerrit: Code review bypass via incorrect authorization
gerrit: Gerrit: Code review bypass via incorrect authorization
A flaw was found in Gerrit. An authenticated attacker with force push permissions on a secondary branch can exploit an incorrect authorization vulnerability within the "submitted together" feature. By crafting a submission that matches the "topic" tag of an unapproved change, the attacker can bypass code review. This allows them to forcefully submit code to restricted branches, potentially leading to unauthorized changes in the codebase.
Package: rh-podman-desktop.git (Red Hat Build of Podman Desktop) - Not affected
Package: rhdh/rhdh-hub-rhel9 (Red Hat Developer Hub) - Not affected
Package: gerrit-api (Red Hat Fuse 7) - Not affected
Package: ansible-automation-platform/automation-portal (Self-service automation portal 2)
GHSA
GHSA-h457-956r-2pr8: Incorrect authorization in the "submitted together" feature in Gerrit versions 2
ghsa_unreviewed·2026-05-13
CVE-2026-2725 [MEDIUM] CWE-863 GHSA-h457-956r-2pr8: Incorrect authorization in the "submitted together" feature in Gerrit versions 2
Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.
No detection rules found.
No public exploits indexed.
2026-05-13
Published