Improper Authorization Vulnerability in GitLab EE
CVE-2026-19228
8.5HIGH
What is CVE-2026-19228?
An improper authorization vulnerability exists in GitLab EE that could allow an authenticated user to misattribute AI usage to another namespace. This issue affects all versions from 19.1 up to 19.1.4 and from 19.2 up to 19.2.2. By exploiting this flaw, attackers could manipulate identity information provided in requests, potentially impacting the integrity of data within the system.
Affected Version(s)
GitLab 19.1 < 19.1.4
GitLab 19.2 < 19.2.2
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by GitLab team member Dennis Appelt