{"id":"CVE-2026-2725","title":"Incorrect authorization in the \"submitted together\" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restrict…","summary":"Incorrect authorization in the \"submitted together\" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restrict…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-863"],"vendor":"google","product":"gerrit","affected":["gerrit >= 2.12"],"published":"2026-05-13","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-2725","references":[{"url":"https://issues.gerritcodereview.com/issues/486131256","label":"cve-coordination@google.com"},{"url":"https://issues.gerritcodereview.com/issues/486131256","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00116,"epssPercentile":0.01795,"ingestedAt":"2026-07-01T09:50:45.564Z","slug":"CVE-2026-2725","body":"## Overview\n\nIncorrect authorization in the \"submitted together\" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the \"topic\" tag of an unapproved change.\n\n## Affected\n\n- `gerrit >= 2.12`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}