Access Control Vulnerability in GitLab CE/EE
CVE-2026-3855
3.1LOW
What is CVE-2026-3855?
An issue has been identified in GitLab CE/EE that affects multiple versions where an authenticated user with project-level permissions can exploit improper validation of parameters within the Terraform state upload functionality. This flaw could inadvertently allow access to restricted file contents stored on the server or facilitate a denial of service condition, potentially compromising system integrity and confidentiality. GitLab has released patches to address these vulnerabilities in subsequent version updates.
Affected Version(s)
GitLab 18.2.7 < 19.1.8
GitLab 19.2 < 19.2.6
GitLab 19.3 < 19.3.2
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [ahacker1](https://hackerone.com/ahacker1) for reporting this vulnerability through our HackerOne bug bounty program