GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
References
| Link | Resource |
|---|---|
| https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/ | Release Notes |
| https://gitlab.com/gitlab-org/gitlab/-/issues/565412 | Broken Link |
| https://hackerone.com/reports/3262844 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-12 20:17
Updated : 2026-08-19 16:32
NVD link : CVE-2025-9486
Mitre link : CVE-2025-9486
CVE.ORG link : CVE-2025-9486
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-266
Incorrect Privilege Assignment
