CVE-2026-1663: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the group import process under certain circumstances.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the group import process under certain circumstances.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1663?
CVE-2026-1663 has a moderate severity, as it involves missing authorization in GitLab that could allow unauthorized label creation in private projects.
How do I fix CVE-2026-1663?
To address CVE-2026-1663, upgrade to GitLab versions 18.7.6, 18.8.6, or 18.9.2, as these versions contain the necessary remediation.
Who is affected by CVE-2026-1663?
CVE-2026-1663 affects all GitLab CE/EE versions from 14.4 through versions prior to 18.7.6, 18.8.6, and 18.9.2.
What is the risk of not addressing CVE-2026-1663?
If not addressed, CVE-2026-1663 can allow authenticated users with group import permissions to create labels in projects that should be private, leading to information exposure.
Is there a patch available for CVE-2026-1663?
Yes, GitLab has released patches for CVE-2026-1663 in versions 18.7.6, 18.8.6, and 18.9.2.