GitLabCVE-2026-6336
GitLab: missing authorization
Medium5.3CVE-2026-6336 · Published Jul 29, 2026 · updated Aug 3, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing authorization check.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 16.6, < 19.0.5 | 19.0.5 |
| >= 19.1, < 19.1.3 | 19.1.3 | |
| >= 19.2, < 19.2.1 | 19.2.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | GitLab: information disclosure | High8.5 | 19.0.5+2 more |
| Jul 29 | GitLab: cross-site scripting | Medium4.7 | 19.0.5+2 more |
| Jul 29 | GitLab: improper access control | Medium4.3 | 19.0.5+2 more |
| Jul 29 | GitLab: denial of service | High7.5 | 19.0.5+2 more |
| Jul 29 | GitLab: information disclosure | Medium5.4 | 19.0.5+2 more |
| Jul 29 | GitLab: improper authorization | Medium4.9 | 19.0.5+2 more |