CVE-2026-14351: Exposure of Sensitive Information Through Metadata in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14351?
The severity of CVE-2026-14351 is medium with a score of 4.3.
How do I fix CVE-2026-14351?
To fix CVE-2026-14351, update your GitLab CE/EE to version 19.0.5 or later, 19.1.3 or later, or 19.2.1 or later.
What type of vulnerability is CVE-2026-14351?
CVE-2026-14351 is a vulnerability that exposes sensitive information through metadata in GitLab.
Who is affected by CVE-2026-14351?
CVE-2026-14351 affects all versions of GitLab CE/EE from 8.8 up to but not including 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.
What could an attacker do with CVE-2026-14351?
An attacker could potentially view the title of a confidential issue through a publicly accessible merge request under certain conditions.