Executive brief
GitLab Enterprise Edition contains a vulnerability that allows users with auditor-level permissions to modify compliance violation records. Normally, these users should only have read-only access to such data. This could allow an internal user to tamper with audit trails or compliance history, potentially impacting the integrity of regulatory reporting.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in GitLab Enterprise Edition (EE) within the compliance violation management component. The flaw is rooted in improper authorization checks on specific GraphQL operations, which fail to enforce read-only restrictions for users with the 'auditor' role. An attacker with high-privileged auditor access can exploit this over the network to modify compliance records that should be immutable to them. The issue affects versions 18.2 through 18.11.6, 19.0 through 19.0.3, and 19.1 through 19.1.1. It has been remediated in versions 18.11.7, 19.0.4, and 19.1.2.
Affected products
- GitLab GitLab Enterprise Edition 18.2 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched
- 2026-07-08: advisory