CVE-2026-1732: Information Disclosure issue in inaccessible issues impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1732?
CVE-2026-1732 is classified as an information disclosure vulnerability that could allow authenticated users to access confidential issue titles.
How do I fix CVE-2026-1732?
To remediate CVE-2026-1732, upgrade GitLab to version 18.7.6, 18.8.6, or 18.9.2 or later.
Which versions of GitLab are affected by CVE-2026-1732?
CVE-2026-1732 affects GitLab CE/EE versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2.
Can CVE-2026-1732 be exploited remotely?
CVE-2026-1732 requires authentication, so it cannot be exploited remotely by unauthenticated users.
What types of data could be exposed due to CVE-2026-1732?
CVE-2026-1732 could potentially expose confidential issue titles to authenticated users who should not have access.