Incorrect authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2025-14562
Published: July 29, 2026 / Updated: July 30, 2026
GitLab Enterprise Edition
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote user to commit changes to a project after being removed as a member.
The vulnerability exists due to improper authorization checks in merge request collaboration settings when handling collaboration settings. A remote user can use merge request collaboration settings to commit changes to a project after being removed as a member.
The issue affects users who previously had developer-role permissions.