CVE-2026-2619: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.
Other sources
GitLab has remediated an issue that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.9Fixed in 18.9.5Fixed in 18.10.3 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.8.9 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.9.5 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.10.3
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-2619?
CVE-2026-2619 has been classified as a medium-severity vulnerability due to its potential for incorrect authorization.
How do I fix CVE-2026-2619?
To fix CVE-2026-2619, users should upgrade their GitLab EE installation to versions 18.8.9, 18.9.5, or 18.10.3.
What versions of GitLab EE are affected by CVE-2026-2619?
CVE-2026-2619 affects GitLab EE versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3.
Who is impacted by CVE-2026-2619?
CVE-2026-2619 impacts all authenticated users of GitLab EE versions that fall within the specified ranges.
What type of vulnerability is CVE-2026-2619?
CVE-2026-2619 is categorized as an Incorrect Authorization issue affecting access to the AI detection API.