Improper Authorization Vulnerability in GitLab EE
CVE-2026-19228

8.5HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-19228?

An improper authorization vulnerability exists in GitLab EE that could allow an authenticated user to misattribute AI usage to another namespace. This issue affects all versions from 19.1 up to 19.1.4 and from 19.2 up to 19.2.2. By exploiting this flaw, attackers could manipulate identity information provided in requests, potentially impacting the integrity of data within the system.

Affected Version(s)

GitLab 19.1 < 19.1.4

GitLab 19.2 < 19.2.2

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team member Dennis Appelt
.