What is CVE-2025-9486?
This vulnerability in GitLab EE allows users with pending memberships to incorrectly gain permissions from a custom role under certain conditions, affecting versions before the patched releases. Administrators should upgrade to the fixed versions 19.0.6, 19.1.4, or 19.2.2 immediately to mitigate the issue.
Azərbaycanca: Bu boşluq GitLab EE platformasında aşkar edilib, 15.6-dan əvvəlki versiyalara qədər təsir göstərir və gözləmədə olan üzvlüyə malik istifadəçilərə xüsusi rol icazələrinin səhv təyin edilməsinə səbəb ola bilər. Təhlükəsizlik tədbiri olaraq GitLab-ı ən son yamaqlanmış versiyalara (19.0.6, 19.1.4, 19.2.2+) yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: GitLab
FAQ2
What version of GitLab is affected by CVE-2025-9486?
This vulnerability affects GitLab EE versions before the patched releases.
What should administrators do to fix CVE-2025-9486?
Administrators should immediately upgrade to the fixed versions 19.0.6, 19.1.4, or 19.2.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.