CVE Vulnerabilities

CVE-2025-7691

Privilege Defined With Unsafe Actions

Published: Sep 26, 2025 | Modified: Sep 29, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab16.6.0 (including)18.2.7 (excluding)
GitlabGitlab18.3.0 (including)18.3.3 (excluding)
GitlabGitlab18.4.0 (including)18.4.0 (including)

Potential Mitigations

References