CVE-2025-10871: Improper Authorization issue for Project Maintainers when assigning roles impacts GitLab EE
An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.
Other sources
GitLab has remediated an issue that could allow Project Maintainers improper authorization to assign custom roles to users exceeding the Project Maintainer’s security boundary and achieving elevated privileges.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10871?
CVE-2025-10871 is a high severity vulnerability allowing Project Maintainers to assign inappropriate permissions to users.
How do I fix CVE-2025-10871?
To fix CVE-2025-10871, upgrade GitLab EE to version 18.2.7, 18.3.3, or 18.4.1 or later.
Who is affected by CVE-2025-10871?
CVE-2025-10871 affects all versions of GitLab EE from 16.6 through 18.2.6, 18.3 through 18.3.2, and 18.4 through 18.4.0.
What types of permissions can be exploited in CVE-2025-10871?
In CVE-2025-10871, Project Maintainers can exploit the system to assign roles that exceed the permissions intended for their own role.
What should I do if I cannot upgrade to the patched versions for CVE-2025-10871?
If unable to upgrade for CVE-2025-10871, review and restrict user role assignments to prevent unauthorized privilege escalation.