Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2805 articles · 108988 vulns · 38/41 feeds (7d)
← Back to list
3.7
CVE-2025-14592PATCHED
gitlab · gitlab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authentic

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

Affected Products

VendorProductVersions
gitlabgitlab< 18.6.6, < 18.6.6, < 18.7.4, < 18.7.4, < 18.8.4, < 18.8.4

References

  • https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/(Release Notes, Vendor Advisory)
  • https://gitlab.com/gitlab-org/gitlab/-/issues/583961(Broken Link, Issue Tracking)
  • https://hackerone.com/reports/3451435(Permissions Required, Exploit)
CVSS 3.13.7 LOW
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
18.6.618.7.418.8.4
CWECWE-862
PublishedFeb 11, 2026
Last enriched7d ago
Trending Score0
Source articles0
Independent0
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVE
Multiple vulnerabilities in GitLab CE and EE prior to 18.10.3, 18.9.5, and 18.8.9
Trending: 20
MEDIUMCVE-2026-4332
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
LOWCVE-2026-4916
Missing Authorization in GitLab
MEDIUMCVE-2026-1516
Improper Control of Generation of Code ('Code Injection') in GitLab
MEDIUMCVE-2026-2619
Incorrect Authorization in GitLab

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Feb 11, 2026
Patch Available
Feb 13, 2026
Discovered by ZDM
Apr 1, 2026