Skip to content
GitLabCVE-2026-4523

GitLab: improper authorization

Low3.7CVE-2026-4523 · Published Sep 29, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.

GitLab advisory

Affected versions

PackageAffectedFixed in
GitLab
Product
>= 15.11, < 19.2.719.2.7
>= 19.3, < 19.3.319.3.3
>= 19.4, < 19.4.119.4.1
Details and references

More GitLab advisories

All GitLab
Advisory
GitLab: missing authorization
Medium4.3Sep 29
GitLab: cross-site scripting
High8.7Sep 29
GitLab: improper authorization
Medium4.3Sep 29
GitLab: code execution
Critical9.9Sep 24
GitLab: missing authorization
High7.7Sep 24
GitLab: improper authorization
Medium4.3Sep 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.