Executive brief
GitLab Enterprise Edition, a platform for software development and collaboration, contained a flaw in how it manages user permissions. An authenticated user with 'auditor' status could have modified vulnerability data in private projects they should not have been able to edit. This could lead to the unauthorized modification of security records, potentially masking known risks within a private codebase.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the GitLab Enterprise Edition (EE) vulnerability flags AI detection API. The flaw allows an authenticated user with auditor-level privileges to bypass intended access controls and modify vulnerability flag data within private projects. The attack is network-based and requires low privileges (auditor role) but no user interaction. GitLab has addressed this issue in versions 18.8.9, 18.9.5, and 18.10.3.
Affected products
- GitLab GitLab Enterprise Edition 18.6 to 18.8.8, 18.9 to 18.9.4, 18.10 to 18.10.2
Timeline
- 2026-04-08: disclosed
- 2026-04-08: patched
- 2026-04-08: advisory