Access Control Vulnerability in GitLab CE/EE
CVE-2026-3160

5.8MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-3160?

An access control vulnerability in GitLab CE/EE could allow an authenticated user to view Jira issues outside of their configured project scope. This issue arises from an integration filter that operates merely as a display control, failing to enforce necessary access boundaries. Users are advised to update to the latest versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

GitLab 13.7 < 18.9.7

GitLab 18.10 < 18.10.6

GitLab 18.11 < 18.11.3

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [maksyche](https://hackerone.com/maksyche) for reporting this vulnerability through our HackerOne bug bounty program
.