Executive brief
GitLab has fixed a security flaw in its Enterprise Edition that could allow a logged-in user with limited permissions to view project information they should not be able to see. This issue stems from insufficient authorization checks within the Security Dashboard component. While the risk is considered low, an attacker could potentially gather internal project details to aid in further unauthorized activities.
Technical details
A missing authorization vulnerability (CWE-862) exists in the GitLab Enterprise Edition (EE) Security Dashboard. The flaw allows an authenticated user with low privileges to bypass intended access controls and view project information due to insufficient authorization checks under specific conditions. The attack vector is network-based and requires low privileges, though it has high complexity. GitLab has released patches in versions 18.11.6, 19.0.3, and 19.1.1 to remediate this issue.
Affected products
- GitLab GitLab Enterprise Edition 18.6 to 18.11.5, 19.0 to 19.0.2, 19.1 to 19.1.0
Timeline
- 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, 18.11.6
- 2026-06-25: disclosed: CVE-2026-3176 published