Authorization Flaw in GitLab EE Affects Multiple Versions
CVE-2026-4879

4.3MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-4879?

GitLab EE versions earlier than 19.0.6, 19.1.4, and 19.2.2 are impacted by an authorization flaw that allows authenticated users with developer-role permissions to access restricted external status check configurations. This issue arises due to a lack of proper authorization checks on the merge request API endpoint, enabling unauthorized visibility into sensitive configurations normally restricted to higher-privileged roles.

Affected Version(s)

GitLab 16.0 < 19.0.6

GitLab 19.1 < 19.1.4

GitLab 19.2 < 19.2.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [jaykp](https://hackerone.com/jaykp) for reporting this vulnerability through our HackerOne bug bounty program
.