CVE-2026-2725: Improper Authorization in Gerrit allowing Code Review Bypass via "Submitted Together"
Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2725?
CVE-2026-2725 has a high severity due to its potential to allow authenticated attackers to bypass code review.
How do I fix CVE-2026-2725?
To fix CVE-2026-2725, upgrade Gerrit to the latest version that addresses this authorization issue.
Which versions of Gerrit are affected by CVE-2026-2725?
CVE-2026-2725 affects Gerrit versions 2.12 and later.
What vulnerabilities are introduced by CVE-2026-2725?
CVE-2026-2725 introduces vulnerabilities related to improper authorization, allowing code review bypass.
Who is at risk from CVE-2026-2725?
Authenticated users with force push permissions on secondary branches are at risk from CVE-2026-2725.