Authorization Flaw in GitLab CE/EE Impacts Project Member Privacy
CVE-2026-8144

4.3MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-8144?

An authorization issue exists in GitLab CE/EE that allows an authenticated user with project membership to enumerate private group members due to insufficient authorization checks. This vulnerability affects multiple versions of GitLab, posing a risk to user privacy and group integrity. Users are encouraged to update to the latest versions to mitigate this risk.

Affected Version(s)

GitLab 15.1 < 18.9.7

GitLab 18.10 < 18.10.6

GitLab 18.11 < 18.11.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team member Terri Chu
.