Junglewise Threat Intelligence

CVE-2026-13151: GitLab Enterprise Edition incorrect authorization in group-level settings

CVE-2026-13151 · Severity: low · CVSS 2.7 · Published 2026-07-08

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab has fixed a security flaw in its Enterprise Edition that could allow certain authorized users to change group-level settings they should not have access to. This issue affects organizations using GitLab to manage software development teams and could lead to unauthorized configuration changes within a group. While the risk is low because it requires high-level existing permissions, it represents a breakdown in the platform's access control rules.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in GitLab EE within the group-level settings component. The flaw stems from improper authorization controls that fail to strictly enforce permission boundaries under specific conditions. An attacker must be authenticated and already possess high-privileged permissions (PR:H) to exploit this via the network. Successful exploitation allows the attacker to modify group configurations that should be restricted, though it does not grant access to sensitive data or impact service availability. The issue is resolved in versions 18.11.7, 19.0.4, and 19.1.2.

Affected products

  • GitLab GitLab Enterprise Edition 16.10 to 18.11.7, 19.0 to 19.0.4, 19.1 to 19.1.2

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched

References

Related threats