Improper Authorization Vulnerability in GitLab CE/EE
CVE-2026-8667
4.3MEDIUM
What is CVE-2026-8667?
A vulnerability in GitLab CE/EE allows authenticated users with a developer role to modify specific package registry metadata without the necessary maintainer-level permissions, due to inadequate authorization checks. This issue affects multiple versions and can pose risks to the integrity of package management within the platform.
Affected Version(s)
GitLab 17.6 < 19.0.6
GitLab 19.1 < 19.1.4
GitLab 19.2 < 19.2.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [peppersghost](https://hackerone.com/peppersghost) for reporting this vulnerability through our HackerOne bug bounty program