Description
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint.
Published: 2026-08-12
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab Enterprise Edition includes a missing authorization check on a project update endpoint. This flaw allows an authenticated user to change project settings that should only be accessible to higher‑privileged roles, enabling the user to persist unauthorized configuration changes.

Affected Systems

GitLab Enterprise Edition versions 19.1 before 19.1.4 and 19.2 before 19.2.2. All newer releases are secure.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability. EPSS data is not available, so exploitation likelihood cannot be quantified. The issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated account; once logged in, a user can modify settings that should be protected, leading to an unauthorized configuration state.

Generated by OpenCVE AI on August 12, 2026 at 23:52 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.4, 19.2.2 or above.


OpenCVE Recommended Actions

  • Upgrade to GitLab 19.1.4, 19.2.2, or a later release that incorporates the missing authorization fix.
  • Confirm that role‑based access controls remain correctly applied to all project settings to prevent unauthorized modifications.
  • Enable audit logging for project settings changes, and configure alerts to detect any unexpected adjustments.

Generated by OpenCVE AI on August 12, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint.
Title Missing Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-862
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-12T19:04:36.421Z

Reserved: 2026-07-21T16:34:08.178Z

Link: CVE-2026-16494

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:37.640

Modified: 2026-08-12T20:17:37.640

Link: CVE-2026-16494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:00:09Z

Weaknesses