CVE-2026-19228
Analyzed Analyzed - Analysis Complete

AI Usage Attribution Bypass in GitLab EE

Vulnerability report for CVE-2026-19228, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-19

Assigner: GitLab Inc.

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-19
Generated
2026-09-02
AI Q&A
2026-08-13
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gitlab gitlab From 19.1.0 (inc) to 19.1.4 (exc)
gitlab gitlab From 19.2.0 (inc) to 19.2.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in GitLab EE allows an authenticated user to manipulate AI usage attribution to another namespace due to improper authorization of identity information in requests. It affects versions 19.1 before 19.1.4 and 19.2 before 19.2.2.

Detection Guidance

This vulnerability affects GitLab EE versions before 19.1.4 and 19.2.2. To detect it, check your GitLab version using commands like 'gitlab-rake gitlab:env:info' or 'cat /opt/gitlab/version-manifest.txt'. If you are running an affected version, update immediately to 19.1.4 or 19.2.2 or later.

Impact Analysis

An attacker could falsely attribute AI usage to another user or group, potentially causing confusion, misuse of resources, or misrepresentation of activity. This could lead to disputes or incorrect billing if AI usage is tracked.

Compliance Impact

This vulnerability could lead to improper attribution of AI usage, potentially causing data processing activities to be misassigned. This may impact compliance by creating inaccuracies in audit logs and activity tracking required by standards like GDPR and HIPAA.

Mitigation Strategies

Update GitLab EE to version 19.1.4 or later if using 19.1.x, or to version 19.2.2 or later if using 19.2.x. This addresses the improper authorization issue causing AI usage attribution to incorrect namespaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19228. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart