Improper Authorization in GitLab CE/EE Allows Issue Manipulation
CVE-2026-1322

6.8MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-1322?

A flaw in GitLab CE/EE exposes private projects to potential misuse by enabling authenticated users with read_api scoped OAuth applications to create issues and comment on them, thanks to insufficient authorization checks. This vulnerability impacts multiple versions and necessitates immediate remediation to secure sensitive project data.

Affected Version(s)

GitLab 16.0 < 18.9.7

GitLab 18.10 < 18.10.6

GitLab 18.11 < 18.11.3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [mateuszek](https://hackerone.com/mateuszek) for reporting this vulnerability through our HackerOne bug bounty program
.