Improper Authorization Vulnerability in GitLab EE Affects Multiple Versions
CVE-2026-18244
4.3MEDIUM
What is CVE-2026-18244?
A security flaw has been identified in GitLab EE that permits authenticated users to view restricted configuration settings under certain conditions. The vulnerability arises due to inadequate authorization checks on the group settings page. Affected versions include 17.7 through 19.0.5, 19.1.0 through 19.1.3, and 19.2.0 through 19.2.1. Remediation has been implemented in the latest updates to safeguard against unauthorized access to sensitive configurations.
Affected Version(s)
GitLab 17.7 < 19.0.6
GitLab 19.1 < 19.1.4
GitLab 19.2 < 19.2.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by GitLab team member Félix Veillette-Potvin