MEDIUM

CVE-2026-4524

Gitlab GitLab 2026-05-14 CVSS v3.1
CVSS
6.5

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access confidential issue content in public projects without proper authorization due to improper authorization checks.

Summary dbcve.org

This is an improper authorization vulnerability in GitLab CE/EE where authenticated users could access confidential issue content in public projects without proper authorization. The vulnerability stems from insufficient authorization checks that should restrict access to confidential issues, allowing any authenticated user to view restricted content in otherwise public projects.

Mitigation

Upgrade GitLab to version 18.9.7, 18.10.6, or 18.11.3 or later to receive the security patch. Organizations should also audit access logs for unauthorized access to confidential issues in public projects.

Weakness (CWE)

CWE-288

EPSS Score

0.29%
Probability of exploitation in next 30 days
21.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE