Authentication Bypass Vulnerability in GitLab EE
CVE-2026-6821

4.3MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-6821?

GitLab EE has addressed a significant issue affecting various versions where authenticated users could potentially bypass IP-based access controls. This vulnerability arose from inadequate authorization checks within the merge requests API endpoint. As a result, affected users might gain access to sensitive merge request information from private projects, posing a risk to project confidentiality. It is crucial for users of GitLab EE versions from 12.0 to 19.2.2 to ensure that they update to the latest release to mitigate this risk.

Affected Version(s)

GitLab 12.0 < 19.0.6

GitLab 19.1 < 19.1.4

GitLab 19.2 < 19.2.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [rogerace](https://hackerone.com/rogerace) for reporting this vulnerability through our HackerOne bug bounty program
.