CVE-2026-13151: Incorrect Authorization in GitLab
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.11.7 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.0.4 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13151?
The severity of CVE-2026-13151 is medium with a score of 4.3.
How do I fix CVE-2026-13151?
To fix CVE-2026-13151, upgrade to GitLab versions 18.11.7, 19.0.4, or 19.1.2 or later.
What is the impact of CVE-2026-13151?
CVE-2026-13151 could allow an authenticated user to modify group-level settings beyond their intended permissions.
Which versions of GitLab are affected by CVE-2026-13151?
CVE-2026-13151 affects GitLab EE versions from 16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2.
What is the nature of the vulnerability in CVE-2026-13151?
CVE-2026-13151 is an incorrect authorization issue in GitLab.