Access Control Vulnerability in GitLab CE/EE
CVE-2026-3160
5.8MEDIUM
What is CVE-2026-3160?
An access control vulnerability in GitLab CE/EE could allow an authenticated user to view Jira issues outside of their configured project scope. This issue arises from an integration filter that operates merely as a display control, failing to enforce necessary access boundaries. Users are advised to update to the latest versions to mitigate the risks associated with this vulnerability.
Affected Version(s)
GitLab 13.7 < 18.9.7
GitLab 18.10 < 18.10.6
GitLab 18.11 < 18.11.3
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [maksyche](https://hackerone.com/maksyche) for reporting this vulnerability through our HackerOne bug bounty program