Junglewise Threat Intelligence

CVE-2026-3607: GitLab CE/EE improper access control in package protection rules

CVE-2026-3607 · Severity: medium · CVSS 4.3 · Published 2026-05-14

Technologies: GitLab Enterprise Edition (EE), GitLab Community Edition. Vendors: GitLab.

Executive brief

GitLab has addressed a security flaw that allowed users with developer-level access to bypass rules designed to protect software packages. This could allow unauthorized modifications or deletions of protected packages within the platform. Organizations should update to the latest patched versions to ensure their software supply chain and package integrity remain secure.

Technical details

An improper access control vulnerability (CWE-1280) exists in GitLab CE/EE where access control checks were implemented after the asset was already accessed. This flaw allows an authenticated attacker with 'Developer' role permissions to bypass configured package protection rules. The vulnerability is reachable over the network and does not require user interaction. Successful exploitation allows the attacker to perform unauthorized actions on protected packages, potentially compromising package integrity. GitLab has released patches in versions 18.9.7, 18.10.6, and 18.11.3 to address this issue.

Affected products

  • GitLab GitLab Community Edition (CE) 18.3 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3
  • GitLab GitLab Enterprise Edition (EE) 18.3 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3
  • 2026-05-14: disclosed: CVE-2026-3607 published

References

Related threats