Executive brief
GitLab, a platform used by software teams to manage code and project tasks, has fixed a security flaw that allowed users to view private information they should not have seen. Specifically, an authenticated user could bypass security checks to read 'confidential issues' within public projects. This could lead to the exposure of sensitive internal discussions, security bug reports, or private project roadmaps.
Technical details
An improper authorization check (CWE-288) in GitLab CE/EE versions 18.9.x, 18.10.x, and 18.11.x allows an authenticated attacker to bypass access controls. By utilizing an alternate path or channel, a user with standard login credentials can view the content of issues marked as 'confidential' within projects that are otherwise set to public visibility. This vulnerability results in a loss of confidentiality for sensitive project data. The issue is remediated in versions 18.9.7, 18.10.6, and 18.11.3.
Affected products
- GitLab GitLab Community Edition (CE) 18.9.1 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3
- GitLab GitLab Enterprise Edition (EE) 18.9.1 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3
Timeline
- 2026-05-13: patched: GitLab released versions 18.11.3, 18.10.6, and 18.9.7
- 2026-05-14: disclosed: NVD publication date