Description
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.
Published: 2026-08-12
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when an authenticated user supplies a key that controls namespace attribution for AI usage requests. GitLab fails to enforce proper authorization on that key, allowing the AI usage to be recorded against any namespace the key refers to instead of the user’s own. This misattribution can let an attacker inflate another namespace’s usage, affecting billing reports or usage limits. The weakness is catalogued as an authorization bypass (CWE-639).

Affected Systems

GitLab Enterprise Edition versions 19.1.x before 19.1.4 and 19.2.x before 19.2.2 are impacted. All GitLab EE releases within these ranges are affected. No other vendors or products are listed.

Risk and Exploitability

The CVSS base score of 8.5 indicates a high severity, while the EPSS score is not available, so the exact exploitation likelihood cannot be quantified. The vulnerability is not yet listed in CISA KEV, suggesting no publicly known widespread exploitation to date. Exploitation requires an authenticated user and the ability to send a request with a user‑controlled key. If exploited, the attacker could cause AI usage metrics and associated billing to be attributed to another namespace, potentially leading to fraud or incorrect resource usage enforcement.

Generated by OpenCVE AI on August 12, 2026 at 22:40 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.4, 19.2.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab Enterprise Edition to version 19.1.4, 19.2.2, or later to apply the official fix.
  • If an immediate upgrade is not possible, restrict the ability to supply a custom namespace key in AI usage requests to users with namespace owner or higher roles to prevent unauthorized attribution.
  • Enable monitoring of AI usage logs and audit trails to detect anomalous namespace attribution and investigate any suspicious activity.

Generated by OpenCVE AI on August 12, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.
Title Authorization Bypass Through User-Controlled Key in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-639
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-12T19:04:16.530Z

Reserved: 2026-08-07T09:33:52.229Z

Link: CVE-2026-19228

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:42.213

Modified: 2026-08-12T20:17:42.213

Link: CVE-2026-19228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T22:45:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key