Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-14595
GitLab vulnerability analysis and mitigation

Overview

CVE-2025-14595 is an improper access control vulnerability in GitLab Enterprise Edition (EE) that allows an authenticated user with the Planner role to view security category metadata and attributes in group security configuration. It affects GitLab EE versions 18.6 through 18.8.6, 18.9.0 through 18.9.2, and 18.10.0. The vulnerability was disclosed and patched on March 25, 2026, with a CVSS v3.1 base score of 4.3 (Medium) (GitLab Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), where the GitLab EE GraphQL API fails to properly enforce access control checks for security category metadata in group security configuration endpoints. Under certain conditions, an authenticated user holding the Planner role — a lower-privilege role not intended to have visibility into security settings — can query and retrieve security configuration attributes that should be restricted to higher-privileged roles. The vulnerability requires only network access and low privileges (a valid Planner-role account), with no user interaction needed. The issue was reported via HackerOne (report #3457779) by researcher kamikaze1337 (GitLab Advisory).

Impact

Successful exploitation results in unauthorized disclosure of security category metadata and configuration attributes within GitLab group security settings, representing a confidentiality breach. Integrity and availability are not affected. While the exposed data is limited to security configuration metadata rather than source code or credentials, it could provide an attacker with insight into an organization's security posture and configured security tooling, potentially aiding further targeted attacks (GitLab Advisory, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account with at least Planner-role permissions within the targeted GitLab EE group (GitLab Advisory).

Exploitation steps

  1. Reconnaissance: Identify a GitLab EE instance running a vulnerable version (18.6–18.8.6, 18.9.0–18.9.2, or 18.10.0) and obtain or possess a valid account with at least the Planner role in a target group.
  2. Authentication: Log in to the GitLab instance using the low-privileged Planner-role account.
  3. Craft GraphQL query: Construct a GraphQL API request targeting the group security configuration endpoint to query security category metadata and attributes that should be restricted to higher-privileged roles.
  4. Submit request: Send the crafted GraphQL query to the GitLab API (e.g., via /api/graphql) while authenticated as the Planner-role user.
  5. Retrieve restricted data: Under the vulnerable conditions, the API returns security category metadata and configuration attributes that the Planner role should not have access to, disclosing sensitive security configuration information (GitLab Advisory).

Indicators of compromise

  • Network: Unusual GraphQL POST requests to /api/graphql from accounts with Planner-role permissions querying security configuration fields not typically accessed by that role.
  • Logs: GitLab application logs showing Planner-role users accessing group security configuration endpoints or GraphQL queries referencing security category metadata fields.
  • Behavior: Planner-role accounts making repeated or automated API calls to security configuration resources outside of normal usage patterns.

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: 18.8.7, 18.9.3, and 18.10.1. All self-managed GitLab EE installations running affected versions should upgrade immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. As an interim measure, administrators should audit Planner role assignments in group security configurations and restrict those assignments to trusted users until patching is complete (GitLab Advisory).

Community reactions

The Centre for Cybersecurity Belgium (CCB) issued an advisory warning about multiple high-severity vulnerabilities in the same GitLab patch release, recommending immediate patching. The vulnerability was reported through GitLab's HackerOne bug bounty program by researcher kamikaze1337. General community reaction has been muted given the medium severity and limited impact scope of this specific CVE compared to higher-severity issues in the same patch batch (GitLab Advisory).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-79708HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-78252HIGH8.2
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-86341MEDIUM4.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-8030MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-7514MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management