GitLabCVE-2026-10518
GitLab: improper authorization
Medium4.3CVE-2026-10518 · Published Sep 29, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with guest-level permissions to read private security policy content they were not authorized to access due to improper authorization enforcement.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 17.9, < 19.2.7 | 19.2.7 |
| >= 19.3, < 19.3.3 | 19.3.3 | |
| >= 19.4, < 19.4.1 | 19.4.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | GitLab: missing authorization | Medium4.3 | 19.2.7+2 more |
| Sep 29 | GitLab: cross-site scripting | High8.7 | 19.2.7+2 more |
| Sep 29 | GitLab: improper authorization | Low3.7 | 19.2.7+2 more |
| Sep 24 | GitLab: code execution | Critical9.9 | 19.2.7+2 more |
| Sep 24 | GitLab: missing authorization | High7.7 | 19.2.7+2 more |
| Sep 24 | GitLab: improper authorization | Medium4.3 | 19.2.7+2 more |