CVE-2025-7691: Privilege Escalation issue from within the Developer role impacts GitLab EE
A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.
Other sources
GitLab has remediated an issue that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-7691?
CVE-2025-7691 has a critical severity level due to its potential for privilege escalation.
How do I fix CVE-2025-7691?
To fix CVE-2025-7691, update your GitLab EE installation to version 18.2.7 or later, 18.3.3 or later, or 18.4.1 or later.
What versions of GitLab EE are affected by CVE-2025-7691?
CVE-2025-7691 affects GitLab EE versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1.
Who can exploit CVE-2025-7691?
A developer with specific group management permissions can exploit CVE-2025-7691 to escalate their privileges.
Is CVE-2025-7691 publicly disclosed?
Yes, CVE-2025-7691 has been publicly disclosed and documented in issue trackers and vulnerability databases.