Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement.
Published: 2026-07-29
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab Community Edition and Enterprise Edition releases prior to 19.0.5, 19.1.3, and 19.2.1 allow an authenticated user with guest role permissions to access test report contents they are not authorized to view, which can lead to the disclosure of sensitive data. The flaw is an improper authorization check identified as CWE-862.

Affected Systems

Vulnerable products include GitLab Community Edition and Enterprise Edition. All releases from 18.4 up to, but not including, 19.0.5, 19.1.3, and 19.2.1 are affected. Users should verify the exact minor release of their instance to determine risk.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation. This vulnerability is not listed in CISA KEV. Attackers would need to authenticate to the system and hold a guest role; the flaw is triggered by the presence of a guest user and does not require elevated privileges or remote code execution.

Generated by OpenCVE AI on August 2, 2026 at 07:42 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.0.5, 19.1.3, 19.2.1 or above.


OpenCVE Recommended Actions

  • Upgrade to GitLab version 19.0.5, 19.1.3, 19.2.1 or later.
  • Review project or group settings to remove test report visibility from the guest role and adjust policies accordingly.
  • Perform regular permission audits to detect and correct any unauthorized guest access to test reports.

Generated by OpenCVE AI on August 2, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement.
Title Missing Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-862
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-29T19:35:54.247Z

Reserved: 2026-03-23T21:03:56.356Z

Link: CVE-2026-4672

cve-icon Vulnrichment

Updated: 2026-07-29T19:35:48.084Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T20:17:03.963

Modified: 2026-08-03T14:03:16.267

Link: CVE-2026-4672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T07:45:03Z

Weaknesses