Executive brief
GitLab, a platform used by developers to manage and store software code, has fixed a security flaw that could allow unauthorized users to access sensitive information. Specifically, an attacker could download private debugging symbols from projects they should not have access to. This could lead to the exposure of internal technical details about a company's proprietary software.
Technical details
An authorization bypass vulnerability (CWE-639) exists in GitLab CE/EE due to improper access control. The flaw allows a remote attacker to download private debugging symbols from projects that are otherwise restricted or inaccessible to them. While the advisory description mentions unauthenticated access, the provided CVSS vector (PR:L) suggests low-privileged authenticated access may be required. The issue affects versions 16.7 through 18.11.3 and has been remediated in patches 18.9.7, 18.10.6, and 18.11.3.
Affected products
- GitLab GitLab Community Edition (CE) / Enterprise Edition (EE) 16.7 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3
Timeline
- 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3 to address the issue.
- 2026-05-14: disclosed: CVE-2026-3074 was published.