Junglewise Threat Intelligence

CVE-2026-11379: GitLab Enterprise Edition incorrect authorization in DAST site profile management

CVE-2026-11379 · Severity: medium · CVSS 5.3 · Published 2026-06-25

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition contains a security flaw in its Dynamic Analysis Software Testing (DAST) management component. This vulnerability allows a user with 'Developer' permissions to potentially steal sensitive secrets, such as credentials or API keys, stored within DAST site profiles. Organizations using GitLab's automated security scanning features should update to prevent internal users from accessing unauthorized sensitive data.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in GitLab EE's DAST site profile management. The flaw allows an authenticated user with the 'Developer' role to exfiltrate secrets stored within DAST site profiles under specific conditions. The attack vector is network-based, though it requires high complexity and existing low-level privileges (Developer role). The issue affects GitLab EE versions 13.11 through 18.11.6, 19.0.x before 19.0.3, and 19.1.x before 19.1.1. GitLab has released patches in versions 19.1.1, 19.0.3, and 18.11.6 to remediate this issue.

Affected products

  • GitLab GitLab Enterprise Edition 13.11 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1

Timeline

  • 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, 18.11.6
  • 2026-06-25: disclosed: NVD publication date

References

Related threats