Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
Published: 2026-07-29
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab has a flaw in internal request handling that allows an authenticated user with a Developer role to unknowingly access sensitive information that should be protected by stricter access controls. The attacker can read data that falls outside the developer’s authorized scope, thereby creating a confidentiality breach. This vulnerability is identified as CWE-201, which relates to improper information exposure due to insecure handling of sensitive data.

Affected Systems

GitLab Customer‑Edition and Enterprise‑Edition installations are affected. All versions starting with 10.1.0 up to, but not including, 19.0.5, the 19.1 series below 19.1.3, and the 19.2 series below 19.2.1 contain the flaw.

Risk and Exploitability

The vulnerability carries a high CVSS score of 8.5, indicating significant impact if exploited. The EPSS score of less than 1 % suggests that actual exploitation is currently rare, and the flaw is not registered in the CISA KEV catalog. Exploitation requires authentication as a Developer, implying the attack vector is an authenticated internal request that bypasses the intended access controls.

Generated by OpenCVE AI on August 3, 2026 at 12:59 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.0.5, 19.1.3, 19.2.1 or above.


OpenCVE Recommended Actions

  • Upgrade all GitLab CE/EE installations to version 19.0.5, 19.1.3, 19.2.1 or later.
  • If an upgrade cannot be performed immediately, restrict the Developer role from accessing internal endpoints that can expose sensitive data, and review role permissions to enforce proper access control.
  • Implement network segmentation or add monitoring for privileged user access to internal services that handle sensitive data.

Generated by OpenCVE AI on August 3, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
Title Insertion of Sensitive Information Into Sent Data in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-201
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-31T16:10:45.590Z

Reserved: 2026-04-14T08:04:23.830Z

Link: CVE-2026-6267

cve-icon Vulnrichment

Updated: 2026-07-29T19:37:12.243Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T20:17:13.123

Modified: 2026-08-03T14:02:29.670

Link: CVE-2026-6267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:00:07Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data