Description
GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint.
Published: 2026-08-12
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the merge request API endpoint allows an authenticated user with developer‑level permissions to retrieve external status check configuration that should be visible only to higher‑privileged roles. The flaw does not provide a direct path to arbitrary code execution or full system compromise, but it does expose sensitive configuration data that could be used for further attacks or insider misuse.

Affected Systems

GitLab Enterprise Edition versions from 16.0 up to 18.x, as well as 19.0.x before 19.0.6, 19.1.x before 19.1.4, and 19.2.x before 19.2.2. The vulnerability applies to the GitLab product released by GitLab Inc. The affected CPE indicates all GitLab EE releases without additional restrictions.

Risk and Exploitability

The CVSS score of 4.3 suggests low overall severity, and the EPSS score is not available, indicating limited data on exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The attack would require the attacker to be an authenticated developer and to target a specific merge request endpoint—a scenario that is likely confined to internal use and not publicly exploitable. Nevertheless, the missing authorization could lead to unintended disclosure of configuration data, which may aid other attack vectors. The risk is therefore considered low to moderate in most environments, but it should be mitigated promptly to prevent potential misuse in contexts where the external status check data is valuable.

Generated by OpenCVE AI on August 12, 2026 at 23:09 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.0.6, 19.1.4, 19.2.2 or above.


OpenCVE Recommended Actions

  • Upgrade the GitLab EE installation to a version that includes the patch: 19.0.6, 19.1.4, 19.2.2 or any current release beyond those thresholds.
  • Apply the appropriate upgrade path in a staged environment to confirm compatibility with existing workflows before full deployment.
  • Restrict developer‑role permissions on merge request API calls that expose external status checks until the upgrade is applied.

Generated by OpenCVE AI on August 12, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint.
Title Missing Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-862
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-12T19:05:11.422Z

Reserved: 2026-03-26T06:33:33.568Z

Link: CVE-2026-4879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:44.850

Modified: 2026-08-12T20:17:44.850

Link: CVE-2026-4879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:15:03Z

Weaknesses