GitLabCVE-2026-4523
GitLab: improper authorization
Low3.7CVE-2026-4523 · Published Sep 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 15.11, < 19.2.7 | 19.2.7 |
| >= 19.3, < 19.3.3 | 19.3.3 | |
| >= 19.4, < 19.4.1 | 19.4.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | GitLab: missing authorization | Medium4.3 | 19.2.7+2 more |
| Sep 29 | GitLab: cross-site scripting | High8.7 | 19.2.7+2 more |
| Sep 29 | GitLab: improper authorization | Medium4.3 | 19.2.7+2 more |
| Sep 24 | GitLab: code execution | Critical9.9 | 19.2.7+2 more |
| Sep 24 | GitLab: missing authorization | High7.7 | 19.2.7+2 more |
| Sep 24 | GitLab: improper authorization | Medium4.3 | 19.2.7+2 more |