Junglewise Threat Intelligence

CVE-2026-2619: GitLab Enterprise Edition incorrect authorization in vulnerability flags AI API

CVE-2026-2619 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition, a platform for software development and collaboration, contained a flaw in how it manages user permissions. An authenticated user with 'auditor' status could have modified vulnerability data in private projects they should not have been able to edit. This could lead to the unauthorized modification of security records, potentially masking known risks within a private codebase.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the GitLab Enterprise Edition (EE) vulnerability flags AI detection API. The flaw allows an authenticated user with auditor-level privileges to bypass intended access controls and modify vulnerability flag data within private projects. The attack is network-based and requires low privileges (auditor role) but no user interaction. GitLab has addressed this issue in versions 18.8.9, 18.9.5, and 18.10.3.

Affected products

  • GitLab GitLab Enterprise Edition 18.6 to 18.8.8, 18.9 to 18.9.4, 18.10 to 18.10.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: patched
  • 2026-04-08: advisory

References

Related threats