Junglewise Threat Intelligence

CVE-2026-5796: GitLab CE/EE improper access control in group packages API

CVE-2026-5796 · Severity: medium · CVSS 4.3 · Published 2026-06-25

Technologies: GitLab CE, GitLab EE. Vendors: GitLab.

Executive brief

GitLab is a platform used by software teams to manage code and automate development workflows. A security flaw was found where users with low-level 'Reporter' permissions could view technical details about software packages even if the Package Registry feature was turned off for a project. This could lead to the unauthorized disclosure of internal project metadata to individuals who should not have access to it.

Technical details

An improper access control vulnerability (CWE-863) exists in the group packages feature of GitLab CE/EE. The flaw stems from incorrect authorization checks that fail to respect the 'disabled' status of the Package Registry at the project level. An authenticated attacker with Reporter-level group permissions can exploit this over the network to view package metadata that should be restricted. The issue affects versions 13.6 through 18.11.6, 19.0.x before 19.0.3, and 19.1.x before 19.1.1. Patches have been released in versions 18.11.6, 19.0.3, and 19.1.1.

Affected products

  • GitLab GitLab CE/EE 13.6 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1

Timeline

  • 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, 18.11.6
  • 2026-06-25: disclosed: NVD publication date

References

Related threats