CVE-2026-25963: Fleet: Authorization Bypass in certificate template batch deletion for team administrators
A broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within the same Fleet instance.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-25963 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →