CVE-2026-6267
HIGHInsertion of Sensitive Information Into Sent Data in GitLab
Title source: cnaDescription
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
References (3)
Core 3
Core References
Exploit technical-description
exploit
permissions-required
HackerOne Bug Bounty Report #3658324
https://hackerone.com/reports/3658324
Scores
CVSS v3
8.5
EPSS
0.0034
EPSS Percentile
26.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-201
Status
published
Products (3)
GitLab/GitLab
10.1.0 - 19.0.5
GitLab/GitLab
19.1 - 19.1.3
GitLab/GitLab
19.2 - 19.2.1
Published
Jul 29, 2026
Tracked Since
Jul 30, 2026