Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.
Published: 2026-07-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab contains an authorization flaw that allows unauthenticated users to determine whether a private project exists by examining cross‑project reference pages. The issue does not provide code execution, elevated privileges, or data leakage beyond knowledge of project existence. It is a case of improper access control, identified as CWE‑862.

Affected Systems

GitLab Community and Enterprise Editions are affected. All releases from 9.1 up to but excluding 18.11.7, from 19.0 up to but excluding 19.0.4, and from 19.1 up to but excluding 19.1.2 are susceptible.

Risk and Exploitability

The CVSS score of 4.3 classifies this vulnerability as low‑medium severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. Because the issue is not listed in the CISA KEV catalog, it is not known to be actively exploited. The attack vector requires no authentication and leverages publicly accessible cross‑project reference endpoints to confirm the existence of a private project.

Generated by OpenCVE AI on July 26, 2026 at 16:57 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.11.7, 19.0.4, 19.1.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to version 18.11.7, 19.0.4, 19.1.2, or any newer release.
  • Limit unauthenticated access to cross‑project reference endpoints via firewall rules or application‑layer ACLs.
  • Enable detailed logging for all attempts to access cross‑project reference pages and regularly review logs for suspicious activity.

Generated by OpenCVE AI on July 26, 2026 at 16:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 11 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.
Title Missing Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-862
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-09T14:14:15.159Z

Reserved: 2026-04-30T09:04:45.873Z

Link: CVE-2026-7492

cve-icon Vulnrichment

Updated: 2026-07-09T14:14:11.483Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-08T20:46:33Z

Links: CVE-2026-7492 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T17:00:14Z

Weaknesses