Incorrect Privilege Assignment in GitLab Enterprise Edition - CVE-2025-9486
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to assign custom role permissions to a user with a pending membership.
The vulnerability exists due to incorrect privilege assignment in custom roles when applying permissions without accounting for membership state. A remote privileged user can assign a custom role to assign custom role permissions to a user with a pending membership.