Authorization Flaw in GitLab EE Affects Multiple Versions
CVE-2026-4879
4.3MEDIUM
What is CVE-2026-4879?
GitLab EE versions earlier than 19.0.6, 19.1.4, and 19.2.2 are impacted by an authorization flaw that allows authenticated users with developer-role permissions to access restricted external status check configurations. This issue arises due to a lack of proper authorization checks on the merge request API endpoint, enabling unauthorized visibility into sensitive configurations normally restricted to higher-privileged roles.
Affected Version(s)
GitLab 16.0 < 19.0.6
GitLab 19.1 < 19.1.4
GitLab 19.2 < 19.2.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [jaykp](https://hackerone.com/jaykp) for reporting this vulnerability through our HackerOne bug bounty program