Skip to content
GitLabCVE-2026-7492

GitLab: improper authorization

Medium4.3CVE-2026-7492 · Published Jul 8, 2026 · updated Jul 9, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.

GitLab advisory

Affected versions

PackageAffectedFixed in
GitLab
Product
>= 9.1, < 18.11.718.11.7
>= 19.0, < 19.0.419.0.4
>= 19.1, < 19.1.219.1.2
Details and references

More GitLab advisories

All GitLab
Advisory
GitLab: cross-site scripting
High8.7Jul 8
GitLab: missing authorization
Medium4.3Jul 8
GitLab: improper authorization
Low2.7Jul 8
GitLab: improper authorization
Medium4.9Jul 8
GitLab: cross-site scripting
High7.3Jul 8
GitLab: authenticated user could create a repository
Low3.5Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.