CVE-2026-1724: Missing Authentication for Critical Function in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1724?
CVE-2026-1724 is considered a critical vulnerability due to its potential for unauthorized access to sensitive API tokens.
How do I fix CVE-2026-1724?
To remediate CVE-2026-1724, upgrade GitLab EE to versions 18.8.7, 18.9.3, or 18.10.1.
What products are affected by CVE-2026-1724?
CVE-2026-1724 affects GitLab EE versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1.
What type of vulnerability is CVE-2026-1724?
CVE-2026-1724 is classified as an Improper Access Control vulnerability in the GitLab EE GraphQL query.
Who should be concerned about CVE-2026-1724?
Self-hosted GitLab EE administrators should be concerned about CVE-2026-1724 due to its impact on API security.