Junglewise Threat Intelligence

CVE-2026-2601: GitLab Enterprise Edition improper authorization in deployment data

CVE-2026-2601 · Severity: medium · CVSS 4.3 · Published 2026-05-27

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition, a platform used by organizations to manage software development and code repositories, contained a security flaw that could allow certain authorized users to see information they should not have access to. Specifically, a user with 'developer' permissions could view sensitive deployment data belonging to projects they were not fully authorized to see. This could lead to the exposure of internal configuration details or deployment secrets, though it does not allow the attacker to modify code or shut down services.

Technical details

An improper authorization vulnerability (CWE-862) exists in GitLab EE due to insufficient permission checks on deployment data. An authenticated attacker with at least 'developer' role permissions can exploit this flaw over the network to view sensitive project deployment information that should be restricted. The issue affects GitLab EE versions starting from 11.5 and has been remediated in versions 18.10.7, 18.11.4, and 19.0.1. The vulnerability is limited to information disclosure (confidentiality impact) and does not provide a mechanism for data modification or service disruption.

Affected products

  • GitLab GitLab Enterprise Edition 11.5 to <18.10.7, 18.11 to <18.11.4, 19.0 to <19.0.1

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: patched
  • 2026-05-27: advisory

References

Related threats