GitLab EE Privilege Escalation Vulnerability via Custom Role Assignment

Vulnerability

A vulnerability exists in GitLab EE versions 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1. Project Maintainers can exploit this issue by assigning custom roles to users that grant permissions exceeding their own, thereby obtaining elevated privileges.

Impact

Exploitation of this vulnerability allows Project Maintainers to gain unauthorized elevated privileges by manipulating user roles.

Added: Sep 26, 2025, 10:18 AM
Updated: Sep 26, 2025, 3:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.