Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks.
Published: 2026-08-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab identifies a defect in its Package Registry component that, under certain conditions, allows an authenticated user with a developer role to alter metadata of packages that normally require maintainer‑level permissions. This flaw falls under CWE‑863 – Improper Authorization. An attacker who can assume a developer account can make unauthorized changes to package metadata, potentially affecting package integrity and the trust of downstream consumers. The vulnerability does not provide a direct path to arbitrary code execution but does enable privilege escalation within the scope of package metadata management.

Affected Systems

The issue affects GitLab Community Edition and Enterprise Edition installations across multiple major releases. Specifically, all versions newer than or equal to 17.6 and older than 19.0.6, 19.1.x before 19.1.4, and 19.2.x before 19.2.2 are impacted. Users operating on any of these versions should verify whether they are vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity level. Because exploitation requires authentication with a developer‑level account, external attackers face a limited attack surface; however, insider threat or compromised credentials remain viable risks. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no widespread exploitation is currently documented. Nonetheless, the ability to modify package metadata without proper authorization presents a significant risk to the integrity of the software supply chain within affected GitLab environments.

Generated by OpenCVE AI on August 12, 2026 at 23:54 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.0.6, 19.1.4, 19.2.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab CE/EE to version 19.0.6, 19.1.4, 19.2.2 or later
  • If an upgrade cannot be performed immediately, restrict developer accounts from modifying package registry metadata by removing the relevant permissions or disabling the feature until remediation.
  • Audit existing package registry metadata and enable detailed logging of any changes to detect potential unauthorized modifications.

Generated by OpenCVE AI on August 12, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Wed, 12 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-13T14:56:08.625Z

Reserved: 2026-05-15T08:33:39.987Z

Link: CVE-2026-8667

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T18:18:16.283

Modified: 2026-08-19T15:57:10.533

Link: CVE-2026-8667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:00:09Z

Weaknesses