Junglewise Threat Intelligence

CVE-2026-6277: GitLab Enterprise Edition incorrect authorization in project security configuration

CVE-2026-6277 · Severity: medium · CVSS 4.3 · Published 2026-06-11

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition, a platform used by organizations to manage software development and source code, contained a flaw in its permission system. This vulnerability allowed users with the 'Security Manager' role to modify project security settings even if those features had been intentionally disabled by administrators. While this does not expose data directly, it allows unauthorized changes to security configurations, potentially bypassing organizational policy.

Technical details

An incorrect authorization enforcement vulnerability (CWE-863) exists in GitLab EE affecting versions 13.9 through 19.0.2. The flaw allows an authenticated attacker with the Security Manager role to bypass feature flags or administrative toggles to manage project security configurations. This occurs even when the relevant security features are explicitly set to a disabled state. The attack is reachable over the network with low privileges (PR:L) and requires no user interaction. GitLab has released patches in versions 18.10.8, 18.11.5, and 19.0.2 to address this issue.

Affected products

  • GitLab GitLab Enterprise Edition 13.9 to 18.10.8, 18.11 to 18.11.5, 19.0 to 19.0.2

Timeline

  • 2026-06-10: patched: GitLab released versions 18.10.8, 18.11.5, and 19.0.2
  • 2026-06-11: disclosed: NVD publication date

References

Related threats