CVE-2026-4524
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access confidential issue content in public projects without proper authorization due to improper authorization checks.
Summary dbcve.org
This is an improper authorization vulnerability in GitLab CE/EE where authenticated users could access confidential issue content in public projects without proper authorization. The vulnerability stems from insufficient authorization checks that should restrict access to confidential issues, allowing any authenticated user to view restricted content in otherwise public projects.
Mitigation
Upgrade GitLab to version 18.9.7, 18.10.6, or 18.11.3 or later to receive the security patch. Organizations should also audit access logs for unauthorized access to confidential issues in public projects.