Improper Authorization in GitLab CE/EE Allows Issue Manipulation
CVE-2026-1322
6.8MEDIUM
What is CVE-2026-1322?
A flaw in GitLab CE/EE exposes private projects to potential misuse by enabling authenticated users with read_api scoped OAuth applications to create issues and comment on them, thanks to insufficient authorization checks. This vulnerability impacts multiple versions and necessitates immediate remediation to secure sensitive project data.
Affected Version(s)
GitLab 16.0 < 18.9.7
GitLab 18.10 < 18.10.6
GitLab 18.11 < 18.11.3
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [mateuszek](https://hackerone.com/mateuszek) for reporting this vulnerability through our HackerOne bug bounty program