Credential Mismanagement in GitLab CE/EE by GitLab
CVE-2026-6515
5.4MEDIUM
What is CVE-2026-6515?
GitLab has addressed a significant issue in its Community and Enterprise Editions, affecting versions 18.2 through 18.9.5, 18.10 through 18.10.3, and 18.11 through 18.11.0. The vulnerability allowed users to exploit invalid or incorrectly scoped credentials to gain unauthorized access to Virtual Registries, creating potential security risks. Users are advised to upgrade to the latest versions for enhanced protection against such access issues.
Affected Version(s)
GitLab 18.2 < 18.9.6
GitLab 18.10 < 18.10.4
GitLab 18.11 < 18.11.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by GitLab team member David Fernandez