PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14562 GitLab CVE debrief

GitLab CE/EE versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 have an improper authorization issue. An authenticated user with developer-role permissions could commit changes to a project after being removed as a member. This issue affects GitLab users who manage access permissions and monitor project changes. The vulnerability has been remediated in the mentioned versions. GitLab users and administrators should prioritize patching vulnerable versions to prevent potential unauthorized changes.

Vendor
GitLab
Product
Unknown
CVSS
LOW 3.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-29
Original CVE updated
2026-08-03
Advisory published
2026-07-29
Advisory updated
2026-08-03

Who should care

GitLab users and administrators who manage access permissions and monitor project changes should be aware of this issue. They should prioritize patching vulnerable versions to prevent potential unauthorized changes. This issue affects GitLab users with developer-role permissions who could commit changes to a project after being removed as a member. GitLab users should review and update access permissions for developers and monitor project changes for unauthorized activity. Additionally, GitLab users should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Affected product deployments should be confirmed in managed environments and an owner should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Asset inventory should be reviewed to identify potentially affected systems. Source-grounded technical framing without unsupported root-cause or exploit claims should be used to understand the issue. Evidence limits, known and unknown affected scope, and what defenders should verify should be included in the evidence notes. Defensive impact and source-grounded technical framing should be included in the technical summary. An executive overview covering affected product or component, vulnerability class, likely operational impact, source-confidence limits, and review context should be included in the debrief. The issue has been remediated in the mentioned versions and GitLab users should apply patches for GitLab versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. The CVE record indicates that GitLab has remediated an issue affecting versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Authenticated users with developer-role permissions could commit changes to a project after being a a

Technical summary

GitLab CE/EE versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 have an improper authorization issue. An authenticated user with developer-role permissions could commit changes to a project after being removed as a member due to improper authorization checks on merge request collaboration settings. This issue affects GitLab users who manage access permissions and monitor project changes.

Defensive priority

GitLab users should prioritize patching vulnerable versions to prevent potential unauthorized changes.

Recommended defensive actions

  • Apply patches for GitLab versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1
  • Review and update access permissions for developers
  • Monitor project changes for unauthorized activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record indicates that GitLab has remediated an issue affecting versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Authenticated users with developer-role permissions could commit changes to a project after being removed as a member due to improper authorization checks.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:00.067Z and has not been modified since then.