CVE-2026-2601
Analyzed Analyzed - Analysis Complete
Authenticated Developer Access to Sensitive Deployment Data in GitLab EE

Publication date: 2026-05-27

Last updated on: 2026-05-27

Assigner: GitLab Inc.

Description
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-05-27
Generated
2026-05-28
AI Q&A
2026-05-27
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
gitlab gitlab From 18.11.0 (inc) to 18.11.4 (exc)
gitlab gitlab 19.0.0
gitlab gitlab From 11.5.0 (inc) to 18.10.7 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in GitLab Enterprise Edition affects versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1. It allows an authenticated user with developer-role permissions to access sensitive deployment data on projects under certain conditions due to improper authorization checks.


How can this vulnerability impact me? :

The impact of this vulnerability is that a user with developer-level access could gain unauthorized access to sensitive deployment data within projects. This could lead to exposure of confidential information related to deployments, potentially compromising project security or operational details.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should upgrade GitLab EE to a fixed version. Specifically, update to version 18.10.7 or later if you are using the 18.10 series, 18.11.4 or later if using the 18.11 series, or 19.0.1 or later if using the 19.0 series.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

This vulnerability could allow an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.

Access to sensitive deployment data without proper authorization may lead to unauthorized disclosure of sensitive information, which could impact compliance with data protection standards and regulations such as GDPR and HIPAA.

However, specific impacts on compliance depend on the nature of the sensitive data exposed and the regulatory requirements applicable to the affected organization.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart