CVE-2026-2601

MEDIUM

Missing Authorization in GitLab

Title source: cna
STIX 2.1

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.

References (3)

Core 3

Scores

CVSS v3 4.3
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (5)
gitlab/gitlab 19.0.0
GitLab/GitLab 11.5 - 18.10.7
gitlab/gitlab 11.5.0 - 18.10.7
GitLab/GitLab 18.11 - 18.11.4
GitLab/GitLab 19.0 - 19.0.1
Published May 27, 2026
Tracked Since May 28, 2026