VDB
CVE-2025-9486
CVE-2025-9486
PUBLISHED
CVSS 3.3 LOW
Reported by GitLab · Published August 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
Risk Scores
CVSS 3.1
3.3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GitLab | GitLab | 15.6, 19.1, 19.2 |
| GitLab | GitLab | 15.6, 19.1, 19.2 |
Timeline
- Aug 12, 2026 CVE Published
- Aug 13, 2026 Coalition ESS Score
- Aug 15, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
References
- GitLab Issue #565412 issue-trackingpermissions-required
- HackerOne Bug Bounty Report #3262844 technical-descriptionexploitpermissions-required