#VU121078 Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2025-11246
Published: January 7, 2026
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in GraphQL runnerUpdate mutation. A remote user with specific permissions can remove all project runners from unrelated projects by manipulating GraphQL runner associations.