GraphQL API Vulnerability in GitLab Product Affecting Unauthenticated Users
CVE-2026-4523
3.7LOW
What is CVE-2026-4523?
GitLab has addressed a vulnerability found in its Community Edition (CE) and Enterprise Edition (EE) that could potentially enable unauthorized users to access sensitive information from CI/CD job traces. This issue arises from inadequate authorization controls within the GraphQL API, affecting various versions of the product. Under certain conditions, unauthenticated users could exploit this flaw to read sensitive variable values, leading to potential data exposure. Users are strongly advised to update to the latest patched versions to ensure their systems are secure.
Affected Version(s)
GitLab 15.11 < 19.2.7
GitLab 19.3 < 19.3.3
GitLab 19.4 < 19.4.1
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [scyoon](https://hackerone.com/scyoon) for reporting this vulnerability through our HackerOne bug bounty program