CVE-2026-11379: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.11.6 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.0.3 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11379?
The severity of CVE-2026-11379 is classified as medium with a score of 5.3.
How do I fix CVE-2026-11379?
To fix CVE-2026-11379, upgrade GitLab to versions 18.11.6, 19.0.3, or 19.1.1 or higher.
What versions of GitLab are affected by CVE-2026-11379?
CVE-2026-11379 affects all GitLab EE versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1.
What kind of vulnerability is CVE-2026-11379?
CVE-2026-11379 is an incorrect authorization vulnerability that affects DAST site profile management in GitLab.
What can an attacker do with CVE-2026-11379?
An attacker with a Developer role could exfiltrate DAST site profile secrets due to incorrect authorization in GitLab.