
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14595 is an improper access control vulnerability in GitLab Enterprise Edition (EE) that allows an authenticated user with the Planner role to view security category metadata and attributes in group security configuration. It affects GitLab EE versions 18.6 through 18.8.6, 18.9.0 through 18.9.2, and 18.10.0. The vulnerability was disclosed and patched on March 25, 2026, with a CVSS v3.1 base score of 4.3 (Medium) (GitLab Advisory, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization), where the GitLab EE GraphQL API fails to properly enforce access control checks for security category metadata in group security configuration endpoints. Under certain conditions, an authenticated user holding the Planner role — a lower-privilege role not intended to have visibility into security settings — can query and retrieve security configuration attributes that should be restricted to higher-privileged roles. The vulnerability requires only network access and low privileges (a valid Planner-role account), with no user interaction needed. The issue was reported via HackerOne (report #3457779) by researcher kamikaze1337 (GitLab Advisory).
Successful exploitation results in unauthorized disclosure of security category metadata and configuration attributes within GitLab group security settings, representing a confidentiality breach. Integrity and availability are not affected. While the exposed data is limited to security configuration metadata rather than source code or credentials, it could provide an attacker with insight into an organization's security posture and configured security tooling, potentially aiding further targeted attacks (GitLab Advisory, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account with at least Planner-role permissions within the targeted GitLab EE group (GitLab Advisory).
/api/graphql) while authenticated as the Planner-role user./api/graphql from accounts with Planner-role permissions querying security configuration fields not typically accessed by that role.GitLab has released patched versions addressing this vulnerability: 18.8.7, 18.9.3, and 18.10.1. All self-managed GitLab EE installations running affected versions should upgrade immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. As an interim measure, administrators should audit Planner role assignments in group security configurations and restrict those assignments to trusted users until patching is complete (GitLab Advisory).
The Centre for Cybersecurity Belgium (CCB) issued an advisory warning about multiple high-severity vulnerabilities in the same GitLab patch release, recommending immediate patching. The vulnerability was reported through GitLab's HackerOne bug bounty program by researcher kamikaze1337. General community reaction has been muted given the medium severity and limited impact scope of this specific CVE compared to higher-severity issues in the same patch batch (GitLab Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."