PT-2026-34472 · Gitlab · Gitlab Ce/Ee

Published

2026-04-22

·

Updated

2026-04-24

·

CVE-2025-9957

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 11.2 through 18.9.5 GitLab CE/EE versions 18.10 through 18.10.3 GitLab CE/EE versions 18.11 through 18.11.0
Description An improper authorization check allows an authenticated user with project owner permissions to bypass group fork prevention settings under certain conditions.
Recommendations Update to version 18.9.6 Update to version 18.10.4 Update to version 18.11.1

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2025-9957
CVE-2025-9957

Affected Products

Gitlab Ce/Ee