#VU124608 Improper Access Control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2025-14595
Published: March 25, 2026 / Updated: March 26, 2026
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to view security category metadata and attributes in group security configuration.
The vulnerability exists due to improper access control in the GraphQL API when handling queries under certain conditions. A remote user with Planner role can send a specially crafted GraphQL query to view security category metadata and attributes in group security configuration.
Authentication and specific role (Planner) are required to exploit this vulnerability.