Security Advisory

CVE-2026-2725

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 05:32:49
Last updated 2026-07-06 23:17:51
Assigner Google
CVSS score 6.0
State PUBLISHED

Description

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.