Authentication Bypass Vulnerability in GitLab EE
CVE-2026-6821
4.3MEDIUM
What is CVE-2026-6821?
GitLab EE has addressed a significant issue affecting various versions where authenticated users could potentially bypass IP-based access controls. This vulnerability arose from inadequate authorization checks within the merge requests API endpoint. As a result, affected users might gain access to sensitive merge request information from private projects, posing a risk to project confidentiality. It is crucial for users of GitLab EE versions from 12.0 to 19.2.2 to ensure that they update to the latest release to mitigate this risk.
Affected Version(s)
GitLab 12.0 < 19.0.6
GitLab 19.1 < 19.1.4
GitLab 19.2 < 19.2.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [rogerace](https://hackerone.com/rogerace) for reporting this vulnerability through our HackerOne bug bounty program