Junglewise Threat Intelligence

CVE-2026-4672: GitLab CE/EE improper access control in Pipeline Test Report API

CVE-2026-4672 · Severity: medium · CVSS 4.3 · Published 2026-07-29

Technologies: GitLab CE, GitLab EE. Vendors: GitLab.

Executive brief

GitLab has fixed a security flaw in its Community and Enterprise editions that could allow users with low-level 'Guest' permissions to view unauthorized test report data. This issue stems from a failure to properly restrict access to the Pipeline Test Report API. While the impact is limited to viewing specific report contents, it could lead to the exposure of sensitive technical information that should be restricted to higher-privileged team members.

Technical details

An improper access control vulnerability (CWE-862) exists in the GitLab Pipeline Test Report API. The flaw allows an authenticated attacker with Guest-level permissions to bypass intended authorization checks and access the contents of test reports they are not authorized to view. The vulnerability affects GitLab CE/EE versions 18.4 through 19.0.5, 19.1 through 19.1.3, and 19.2 through 19.2.1. The issue has been resolved in versions 19.0.5, 19.1.3, and 19.2.1. Exploitation requires network access and valid low-privileged credentials but no user interaction.

Affected products

  • GitLab GitLab CE/EE 18.4 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1

Timeline

  • 2026-07-29: patched: GitLab released versions 19.2.1, 19.1.3, and 19.0.5 to address the issue.
  • 2026-07-29: advisory: NVD and GitLab published the vulnerability details.

References

Related threats