CVE-2026-1182: Information Disclosure issue in confidential issues impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential issue title created in public projects under certain circumstances.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to gain unauthorized access to confidential issue titles created in public projects under certain circumstances.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1182?
The severity of CVE-2026-1182 is considered high due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2026-1182?
To fix CVE-2026-1182, upgrade your GitLab CE/EE instance to versions 18.7.6, 18.8.6, or 18.9.2 or later.
Who is affected by CVE-2026-1182?
CVE-2026-1182 affects all versions of GitLab CE from 8.14 up to but not including 18.7.6 and GitLab EE from 18.8 to 18.8.6 and 18.9 to 18.9.2.
What type of vulnerability is CVE-2026-1182?
CVE-2026-1182 is classified as an improper removal of sensitive information before storage or transfer.
What can an attacker do with CVE-2026-1182?
An attacker could exploit CVE-2026-1182 to gain unauthorized access to confidential information stored in GitLab.