Credential Mismanagement in GitLab CE/EE by GitLab
CVE-2026-6515

5.4MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-6515?

GitLab has addressed a significant issue in its Community and Enterprise Editions, affecting versions 18.2 through 18.9.5, 18.10 through 18.10.3, and 18.11 through 18.11.0. The vulnerability allowed users to exploit invalid or incorrectly scoped credentials to gain unauthorized access to Virtual Registries, creating potential security risks. Users are advised to upgrade to the latest versions for enhanced protection against such access issues.

Affected Version(s)

GitLab 18.2 < 18.9.6

GitLab 18.10 < 18.10.4

GitLab 18.11 < 18.11.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team member David Fernandez
.