Group Settings Modification Flaw in GitLab by GitLab Inc.
CVE-2026-8030
4.3MEDIUM
What is CVE-2026-8030?
An issue in GitLab CE/EE permitted an authenticated user to inadvertently restrict another user's ability to modify their group settings. This arose due to inadequate validation of group URL slugs during the process of namespace transfers. The flaw manifested in versions prior to 19.1.8, 19.2.6, and 19.3.2, making it critical for users to update their installations promptly to prevent potential misuse. The vulnerability underscores the importance of stringent validation mechanisms in user permissions and group management functionalities.
Affected Version(s)
GitLab 13.0 < 19.1.8
GitLab 19.2 < 19.2.6
GitLab 19.3 < 19.3.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [mateuszek](https://hackerone.com/mateuszek) for reporting this vulnerability through our HackerOne bug bounty program