CVE-2026-6267

HIGH

Insertion of Sensitive Information Into Sent Data in GitLab

Title source: cna
STIX 2.1

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.

References (3)

Core 3
Core References
Exploit technical-description exploit permissions-required
HackerOne Bug Bounty Report #3658324
https://hackerone.com/reports/3658324

Scores

CVSS v3 8.5
EPSS 0.0034
EPSS Percentile 26.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-201
Status published
Products (3)
GitLab/GitLab 10.1.0 - 19.0.5
GitLab/GitLab 19.1 - 19.1.3
GitLab/GitLab 19.2 - 19.2.1
Published Jul 29, 2026
Tracked Since Jul 30, 2026