CVE-2026-4868
8.2GitLab · GitLab EE
GitLab EE contains an authorization bypass vulnerability allowing authenticated users to perform actions via user-controlled keys.
Executive summary
An authorization bypass vulnerability in GitLab EE may allow authenticated users to perform unauthorized actions, necessitating an immediate upgrade to the provided patched versions.
Vulnerability
This is an Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability. It requires low-privileged authenticated access to exploit, potentially permitting users to interact with resources they are not authorized to access.
Business impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive project repositories, metadata, or administrative functions within the GitLab instance. The CVSS score of 8.2 reflects the high risk of unauthorized access and potential data compromise in a collaborative development environment.
Remediation
Immediate Action: Upgrade GitLab EE installations to version 18.10.7, 18.11.4, 19.0.1, or higher immediately.
Proactive Monitoring: Review audit logs and access logs for suspicious activity or unauthorized attempts to access protected resources during the period before the patch was applied.
Compensating Controls: Restrict access to the GitLab instance to trusted networks and ensure that the Principle of Least Privilege is enforced for all user accounts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this authorization bypass necessitates prompt action. Administrators must prioritize the application of the vendor-supplied security updates to ensure the integrity and confidentiality of the GitLab environment.