Authorization Flaw in GitLab EE Allows Modification of Vulnerability Data
CVE-2026-2619
4.3MEDIUM
What is CVE-2026-2619?
An authorization flaw in GitLab EE allows authenticated users with auditor privileges to improperly modify vulnerability flag data in private projects. This occurs due to inadequate permissions checks in specific cases, compromising the integrity of project vulnerability management. GitLab has released patches to address this issue in versions 18.8.9, 18.9.5, and 18.10.3. Users are strongly advised to update to the latest versions to safeguard against potential exploits.
Affected Version(s)
GitLab 18.6 < 18.8.9
GitLab 18.9 < 18.9.5
GitLab 18.10 < 18.10.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [sage_cyberlord](https://hackerone.com/sage_cyberlord) for reporting this vulnerability through our HackerOne bug bounty program