Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement.
Published: 2026-05-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect authorization check in GitLab allows a blocked Project Access Token to continue accessing private resources, effectively bypassing the intended revocation and exposing sensitive project data. The flaw permits unauthorized individuals who possess a blocked token—either through theft or misconfiguration—to gain read or write access to private repositories, compromising confidentiality of source code and potentially enabling further malicious activity. This weakness is classified as CWE-863, signifying an improper authorization mechanism.

Affected Systems

All GitLab Community Edition and Enterprise Edition deployments from version 18.9 up to (but not including) 18.10.7, from 18.11 up to (but not including) 18.11.4, and from 19.0 up to (but not including) 19.0.1 are vulnerable. The affected product is GitLab, managed by GitLab Inc. Users running any of these releases must check their version and address the issue promptly.

Risk and Exploitability

With a CVSS score of 4.3, the vulnerability is considered moderate; the EPSS score is unavailable, so no assessment of current exploitation probability can be made. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large-scale exploitation yet. Likely the attack requires possession of a blocked token and the ability to make API calls to the GitLab instance, making the vector remote through authenticated traffic. Successful exploitation would grant the attacker the same privileges as the token holder, effectively bypassing the blocking mechanism.

Generated by OpenCVE AI on May 28, 2026 at 09:23 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.10.7, 18.11.4, 19.0.1 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to version 18.10.7, 18.11.4, 19.0.1 or newer.
  • After upgrading, test that any blocked Project Access Token is denied access to private resources.
  • Ensure that token revocation is enforced by auditing active tokens and removing any that should be blocked.

Generated by OpenCVE AI on May 28, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*

Thu, 28 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 08:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-05-28T12:11:19.756Z

Reserved: 2026-05-28T07:34:32.961Z

Link: CVE-2026-9807

cve-icon Vulnrichment

Updated: 2026-05-28T12:11:14.806Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T09:16:49.760

Modified: 2026-05-29T16:40:30.443

Link: CVE-2026-9807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T10:00:11Z

Weaknesses