Description
GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement.
Published: 2026-06-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab Enterprise Edition suffered an incorrect authorization bug that, under specific conditions, would allow an authenticated user who held the Security Manager role to configure project security settings even when the feature was intended to be disabled. This flaw permits users to alter security configurations—such as roles, policies, or scanning settings—potentially weakening the overall security posture or bypassing intended controls. The impact is limited to the scope of configuration changes; it does not provide remote code execution or direct data exfiltration, but it can enable further privilege escalation or compromise within the organization.

Affected Systems

The affected product is GitLab Enterprise Edition. All releases from version 13.9 up to but not including 18.10.8, from 18.11 up to but not including 18.11.5, and from 19.0 up to but not including 19.0.2 are vulnerable. Upgrading to 18.10.8, 18.11.5, or 19.0.2 or later resolves the issue.

Risk and Exploitability

With a CVSS score of 4.3 the vulnerability is considered moderate, and its EPSS score is not available, indicating that current exploitation likelihood is uncertain. The flaw is not listed in the CISA KEV catalog, and no public exploit is reported. Attackers need authenticated access as a Security Manager or equivalent role. Because the vulnerability requires specific internal configuration states, the attack vector is inferred to be an internal one, likely requiring an insider or compromised credentials. While it does not directly crash or compromise the system, it can facilitate broader unauthorized actions by others if enabled within the organization.

Generated by OpenCVE AI on June 11, 2026 at 12:22 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.10.8, 18.11.5, 19.0.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab EE to version 18.10.8, 18.11.5, or 19.0.2 or later to apply the official fix.
  • Restrict the assignment of the Security Manager role to trusted personnel and monitor related activity.
  • Temporarily disable or restrict access to project security configuration for disabled features until the upgrade is complete.

Generated by OpenCVE AI on June 11, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-06-11T12:31:03.704Z

Reserved: 2026-04-14T14:05:32.198Z

Link: CVE-2026-6277

cve-icon Vulnrichment

Updated: 2026-06-11T12:30:58.553Z

cve-icon NVD

Status : Received

Published: 2026-06-11T12:16:32.217

Modified: 2026-06-11T12:16:32.217

Link: CVE-2026-6277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T12:30:14Z

Weaknesses