Improper Access Control in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2025-14595
Published: March 25, 2026 / Updated: March 26, 2026
Vulnerability details
The vulnerability allows a remote user to view security category metadata and attributes in group security configuration.
The vulnerability exists due to improper access control in the GraphQL API when handling queries under certain conditions. A remote user with Planner role can send a specially crafted GraphQL query to view security category metadata and attributes in group security configuration.
Authentication and specific role (Planner) are required to exploit this vulnerability.
Affected software
Gitlab Community Edition
How to mitigate CVE-2025-14595
Gitlab Community Edition - addressed in versions 18.8.7, 18.9.3, 18.10.1