Description
GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to modify group-level settings beyond their intended permissions due to improper authorization controls.
Published: 2026-07-08
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in GitLab Enterprise Edition allows an authenticated user to modify group-level settings beyond the permissions intended by the system, because of improper authorization controls (CWE-863).

Affected Systems

All GitLab Enterprise Edition releases from version 16.10 up to, but not including, 18.11.7, as well as 19.0.0 through 19.0.3 and 19.1.0 through 19.1.1. The product is GitLab EE.

Risk and Exploitability

The CVSS score of 2.7 classifies this weakness as low severity, and the EPSS score of less than 1 % indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker must be authenticated within the GitLab instance to exploit the flaw, typically by submitting requests that change group settings that are normally restricted to group owners or administrators.

Generated by OpenCVE AI on July 29, 2026 at 13:25 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.11.7, 19.0.4, 19.1.2 or above.


OpenCVE Recommended Actions

  • Upgrade to GitLab Enterprise Edition 18.11.7, 19.0.4, 19.1.2 or later to remove the authorization flaw
  • Reconfigure group‑level permissions to ensure only owners or administrators can modify settings, addressing the CWE‑863 weakness
  • Perform regular audits of group settings and monitor for unauthorized changes to detect persistence of the issue

Generated by OpenCVE AI on July 29, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to modify group-level settings beyond their intended permissions due to improper authorization controls.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-09T14:25:51.832Z

Reserved: 2026-06-24T10:43:58.146Z

Link: CVE-2026-13151

cve-icon Vulnrichment

Updated: 2026-07-09T14:25:45.939Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:30:06Z

Weaknesses