Description
GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls.
Published: 2026-07-08
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab Enterprise Edition versions prior to the patched releases exposed a flaw in authorization checks, corresponding to CWE-266: Improper Authentication and CWE-522: Sensitive Data Exposure. This flaw could with maintainer role permissions to read other users’ stored credentials when certain conditions were met. The weakness centers on improper authorization controls, allowing credential disclosure to a privileged but non-administrator user.

Affected Systems

GitLab EE is affected, specifically all releases from 9.5 up to but not including 18.11.7, all 19.0 releases up to but not including 19.0.4, and all 19.1 releases up to but not including 19.1.2.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity known at this time. Exploitation requires the attacker to be a legitimate GitLab user with maintainer role privileges; consequently the attack surface is restricted a wide range of users.

Generated by OpenCVE AI on July 29, 2026 at 13:25 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.11.7, 19.0.4, 19.1.2 or above.


OpenCVE Recommended Actions

  • Update GitLab Enterprise Edition to version 18.11.7 or later, or 19.0.4 or 19.1.2 and above to apply the vendor patch.
  • Limit the number of users granted maintainer role privileges and enforce least-privilege policies to reduce the risk window.
  • Audit and monitor credential access logs for unauthorized read attempts and verify that no credential data has been exposed.

Generated by OpenCVE AI on July 29, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls.
Title Insufficiently Protected Credentials in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-522
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-09T14:15:01.193Z

Reserved: 2026-06-09T20:03:57.026Z

Link: CVE-2026-11827

cve-icon Vulnrichment

Updated: 2026-07-09T14:14:57.988Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-08T20:46:23Z

Links: CVE-2026-11827 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:30:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-522

    Insufficiently Protected Credentials