Improper Authorization Vulnerability in GitLab CE/EE
CVE-2026-8667

4.3MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-8667?

A vulnerability in GitLab CE/EE allows authenticated users with a developer role to modify specific package registry metadata without the necessary maintainer-level permissions, due to inadequate authorization checks. This issue affects multiple versions and can pose risks to the integrity of package management within the platform.

Affected Version(s)

GitLab 17.6 < 19.0.6

GitLab 19.1 < 19.1.4

GitLab 19.2 < 19.2.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [peppersghost](https://hackerone.com/peppersghost) for reporting this vulnerability through our HackerOne bug bounty program
.