PatchSiren cyber security CVE debrief
CVE-2025-14562 GitLab CVE debrief
GitLab CE/EE versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 have an improper authorization issue. An authenticated user with developer-role permissions could commit changes to a project after being removed as a member. This issue affects GitLab users who manage access permissions and monitor project changes. The vulnerability has been remediated in the mentioned versions. GitLab users and administrators should prioritize patching vulnerable versions to prevent potential unauthorized changes.
- Vendor
- GitLab
- Product
- Unknown
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-29
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-07-29
- Advisory updated
- 2026-08-03
Who should care
GitLab users and administrators who manage access permissions and monitor project changes should be aware of this issue. They should prioritize patching vulnerable versions to prevent potential unauthorized changes. This issue affects GitLab users with developer-role permissions who could commit changes to a project after being removed as a member. GitLab users should review and update access permissions for developers and monitor project changes for unauthorized activity. Additionally, GitLab users should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Affected product deployments should be confirmed in managed environments and an owner should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Asset inventory should be reviewed to identify potentially affected systems. Source-grounded technical framing without unsupported root-cause or exploit claims should be used to understand the issue. Evidence limits, known and unknown affected scope, and what defenders should verify should be included in the evidence notes. Defensive impact and source-grounded technical framing should be included in the technical summary. An executive overview covering affected product or component, vulnerability class, likely operational impact, source-confidence limits, and review context should be included in the debrief. The issue has been remediated in the mentioned versions and GitLab users should apply patches for GitLab versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. The CVE record indicates that GitLab has remediated an issue affecting versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Authenticated users with developer-role permissions could commit changes to a project after being a a
Technical summary
GitLab CE/EE versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 have an improper authorization issue. An authenticated user with developer-role permissions could commit changes to a project after being removed as a member due to improper authorization checks on merge request collaboration settings. This issue affects GitLab users who manage access permissions and monitor project changes.
Defensive priority
GitLab users should prioritize patching vulnerable versions to prevent potential unauthorized changes.
Recommended defensive actions
- Apply patches for GitLab versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1
- Review and update access permissions for developers
- Monitor project changes for unauthorized activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record indicates that GitLab has remediated an issue affecting versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Authenticated users with developer-role permissions could commit changes to a project after being removed as a member due to improper authorization checks.
Official resources
-
CVE-2025-14562 CVE record
CVE.org
-
CVE-2025-14562 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Release Notes, Vendor Advisory
-
Source reference
[email protected] - Broken Link
-
Source reference
[email protected] - Permissions Required
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:00.067Z and has not been modified since then.