Gerrit · Gerrit · CVE-2026-2725
**Name of the Vulnerable Software and Affected Versions**
Gerrit versions 2.12 and later
**Description**
Incorrect authorization in the "submitted together" feature allows an authenticated attacker with force push permissions on a secondary branch to bypass code review. This is achieved by using a crafted submission that matches the `topic` tag of an unapproved change, enabling the attacker to forcefully submit code to restricted branches.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.