Authorization Flaw in GitLab CE/EE Services
CVE-2025-12716
8.7HIGH
What is CVE-2025-12716?
An authorization flaw exists in GitLab CE/EE that may allow an authenticated user to perform unauthorized actions on behalf of another user. This vulnerability can be exploited by creating wiki pages with malicious content. Affected versions include all releases from 18.4 prior to 18.4.6, 18.5 prior to 18.5.4, and 18.6 prior to 18.6.2. Users should upgrade to patched versions to mitigate the risk of this exploit.
Affected Version(s)
GitLab 18.4 < 18.4.6
GitLab 18.5 < 18.5.4
GitLab 18.6 < 18.6.2
References
CVSS V3.1
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program