EIP-2026-114701

PRE-CVE

GitLab Community Edition (CE) 13.10.3 - 'Sign_Up' User Enumeration

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114701. PoCs published by 4D0niiS.

AI-analyzed exploit summary This exploit demonstrates a user enumeration vulnerability in GitLab CE 13.10.3 by leveraging the sign-up page's username validation endpoint. An unauthenticated attacker can brute-force usernames via the `/users/<username>/exists` endpoint to determine valid users based on the JSON response.

Description

GitLab Community Edition (CE) 13.10.3 - 'Sign_Up' User Enumeration

Exploits (1)

exploitdb WORKING POC
by 4D0niiS · textwebappsruby
https://www.exploit-db.com/exploits/49822

This exploit demonstrates a user enumeration vulnerability in GitLab CE 13.10.3 by leveraging the sign-up page's username validation endpoint. An unauthenticated attacker can brute-force usernames via the `/users/<username>/exists` endpoint to determine valid users based on the JSON response.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: GitLab Community Edition (CE) 13.10.3
No auth needed
Prerequisites: Access to the GitLab instance's sign-up page · Ability to intercept and modify HTTP requests (e.g., Burp Suite)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026