CVE-2025-9486
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
Scoring
- Severity
- LOW
- CVSS base score
- 3.3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-266
- Published
- 2026-08-12
- Last modified
- 2026-08-13
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-78477 — The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This mak
- CVE-2026-84814 — WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability
- CVE-2026-81294 — WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability
- CVE-2026-78330 — Apache Syncope: Privilege escalation for admin user via JWT authentication
- CVE-2026-78267 — WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability
- CVE-2026-73390 — WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability
- CVE-2026-73347 — WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability
- CVE-2026-66682 — WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability