docs.gitlab.com
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released CVE-2025-9486
LOW
Incorrect Privilege Assignment in GitLab
Record summary
CVE-2025-9486 has a selected CVSS score of 3.3 (low).
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GitLabBrowse GitLab / GitLabDefault status: unaffected | CVE List | 15.6 to < 19.0.6 | affected |
| 19.1 to < 19.1.4 | affected | ||
| 19.2 to < 19.2.2 | affected |
References
4GitLab Issue #565412issue trackingpermissions required
https://gitlab.com/gitlab-org/gitlab/-/issues/565412 HackerOne Bug Bounty Report #3262844Technical descriptionexploitpermissions required
https://hackerone.com/reports/3262844 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-9486