CVE-2026-2601
Authenticated Developer Access to Sensitive Deployment Data in GitLab EE
Publication date: 2026-05-27
Last updated on: 2026-05-27
Assigner: GitLab Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gitlab | gitlab | From 18.11.0 (inc) to 18.11.4 (exc) |
| gitlab | gitlab | 19.0.0 |
| gitlab | gitlab | From 11.5.0 (inc) to 18.10.7 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in GitLab Enterprise Edition affects versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1. It allows an authenticated user with developer-role permissions to access sensitive deployment data on projects under certain conditions due to improper authorization checks.
How can this vulnerability impact me? :
The impact of this vulnerability is that a user with developer-level access could gain unauthorized access to sensitive deployment data within projects. This could lead to exposure of confidential information related to deployments, potentially compromising project security or operational details.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, you should upgrade GitLab EE to a fixed version. Specifically, update to version 18.10.7 or later if you are using the 18.10 series, 18.11.4 or later if using the 18.11 series, or 19.0.1 or later if using the 19.0 series.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability could allow an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.
Access to sensitive deployment data without proper authorization may lead to unauthorized disclosure of sensitive information, which could impact compliance with data protection standards and regulations such as GDPR and HIPAA.
However, specific impacts on compliance depend on the nature of the sensitive data exposed and the regulatory requirements applicable to the affected organization.