CVE Vulnerabilities

CVE-2025-7691

Privilege Defined With Unsafe Actions

Published: Sep 26, 2025 | Modified: Sep 29, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 16.6.0 (including) 18.2.7 (excluding)
Gitlab Gitlab 18.3.0 (including) 18.3.3 (excluding)
Gitlab Gitlab 18.4.0 (including) 18.4.0 (including)

Potential Mitigations

References