No advisories yet.
Solution
Upgrade to versions 18.8.9, 18.9.5, 18.10.3 or above.
Workaround
No workaround given by the vendor.
Thu, 09 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization. | |
| Title | Incorrect Authorization in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-04-09T13:04:26.216Z
Reserved: 2026-02-17T07:34:18.595Z
Link: CVE-2026-2619
Updated: 2026-04-09T13:04:22.725Z
Status : Received
Published: 2026-04-08T23:16:58.557
Modified: 2026-04-08T23:16:58.557
Link: CVE-2026-2619
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:25:39Z