GraphQL API Vulnerability in GitLab Product Affecting Unauthenticated Users
CVE-2026-4523

3.7LOW

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-4523?

GitLab has addressed a vulnerability found in its Community Edition (CE) and Enterprise Edition (EE) that could potentially enable unauthorized users to access sensitive information from CI/CD job traces. This issue arises from inadequate authorization controls within the GraphQL API, affecting various versions of the product. Under certain conditions, unauthenticated users could exploit this flaw to read sensitive variable values, leading to potential data exposure. Users are strongly advised to update to the latest patched versions to ensure their systems are secure.

Affected Version(s)

GitLab 15.11 < 19.2.7

GitLab 19.3 < 19.3.3

GitLab 19.4 < 19.4.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [scyoon](https://hackerone.com/scyoon) for reporting this vulnerability through our HackerOne bug bounty program
.