Junglewise Threat Intelligence

CVE-2026-5952: GitLab GitLab CE/EE incorrect authorization in Maven Package Registry

CVE-2026-5952 · Severity: medium · CVSS 4.3 · Published 2026-06-25

Technologies: GitLab CE, GitLab EE. Vendors: GitLab.

Executive brief

GitLab is a platform used by organizations to manage software development and code repositories. A vulnerability in the Maven Package Registry could allow a user with developer-level access to bypass security rules and overwrite protected package metadata. This could lead to the corruption of software build components, potentially affecting the integrity of the software supply chain.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the GitLab Maven Package Registry. The flaw allows an authenticated attacker with 'Developer' role permissions to bypass established package protection rules under specific conditions. By exploiting this, an attacker can overwrite protected Maven package metadata, compromising the integrity of the registry. The issue affects GitLab CE/EE versions 17.11 through 18.11.5, 19.0.x before 19.0.3, and 19.1.x before 19.1.1. Patches have been released in versions 18.11.6, 19.0.3, and 19.1.1.

Affected products

  • GitLab GitLab CE/EE 17.11 before 18.11.6, 19.0 before 19.0.3, 19.1 before 19.1.1

Timeline

  • 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, 18.11.6
  • 2026-06-25: advisory: NVD published the CVE record

References

Related threats