Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to improper authorization checks in the Generic Package Registry.
Published: 2026-09-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Illicit modification and concealment of packages
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in GitLab’s Generic Package Registry, where an authenticated user with a developer role can replace package file content and hide packages from their owners because authorization checks are inadequate. This allows the user to tamper with package distribution and potentially conceal malicious or altered releases, undermining the integrity of the package pipeline.

Affected Systems

Affected systems are GitLab Community and Enterprise Editions. Versions prior to 19.1.8 (for 19.x branches), 19.2 before 19.2.6, and 19.3 before 19.3.2 are vulnerable. Earlier releases from 13.9 onward also fall within the affected range.

Risk and Exploitability

The CVSS score of 4.3 classifies the issue as moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV and no active exploitation has been reported. Attackers must have authenticated access with developer permissions compromised developer accounts. The vendor’s patch is the sole official fix; otherwise restricting developer access or monitoring package activity can help mitigate risk.

Generated by OpenCVE AI on September 16, 2026 at 15:23 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to the supported release versions (19.1.8, 19.2.6, or 19.3.2 or later).
  • Con the Generic Package Registry or temporarily revoke developer access until the patch is applied.
  • Audit package repositories for unexpected changes and enforce least‑privilege access controls.

Generated by OpenCVE AI on September 16, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to improper authorization checks in the Generic Package Registry.
Title Missing Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-862
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-16T15:45:18.169Z

Reserved: 2026-04-30T15:33:45.538Z

Link: CVE-2026-7514

cve-icon Vulnrichment

Updated: 2026-09-16T15:45:14.397Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T07:16:37.560

Modified: 2026-09-16T19:23:34.623

Link: CVE-2026-7514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:30:06Z

Weaknesses