Authorization Flaw in GitLab CE/EE Impacts Project Member Privacy
CVE-2026-8144
4.3MEDIUM
What is CVE-2026-8144?
An authorization issue exists in GitLab CE/EE that allows an authenticated user with project membership to enumerate private group members due to insufficient authorization checks. This vulnerability affects multiple versions of GitLab, posing a risk to user privacy and group integrity. Users are encouraged to update to the latest versions to mitigate this risk.
Affected Version(s)
GitLab 15.1 < 18.9.7
GitLab 18.10 < 18.10.6
GitLab 18.11 < 18.11.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by GitLab team member Terri Chu