Improper Access Control in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2025-14595

 

Improper Access Control in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2025-14595

Published: March 25, 2026 / Updated: March 26, 2026


Vulnerability identifier: #VU124608
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14595
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to view security category metadata and attributes in group security configuration.

The vulnerability exists due to improper access control in the GraphQL API when handling queries under certain conditions. A remote user with Planner role can send a specially crafted GraphQL query to view security category metadata and attributes in group security configuration.

Authentication and specific role (Planner) are required to exploit this vulnerability.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition

How to mitigate CVE-2025-14595

Install security update from vendor's website.

GitLab Enterprise Edition - addressed in versions 18.8.7, 18.9.3, 18.10.1
Gitlab Community Edition - addressed in versions 18.8.7, 18.9.3, 18.10.1

External References

Related Security Bulletins