CVE-2026-3074: Authorization Bypass Through User-Controlled Key in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to download private debugging symbols from inaccessible projects due to improper access control.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3074?
CVE-2026-3074 has a medium severity rating due to its potential for unauthorized access to private debugging symbols.
How do I fix CVE-2026-3074?
To fix CVE-2026-3074, upgrade GitLab CE/EE to versions 18.9.7, 18.10.6, or 18.11.3 or later.
What versions of GitLab are affected by CVE-2026-3074?
CVE-2026-3074 affects GitLab CE/EE versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3.
Can CVE-2026-3074 be exploited remotely?
Yes, CVE-2026-3074 can be exploited by an unauthenticated user accessing private debugging symbols.
What kind of vulnerability is CVE-2026-3074?
CVE-2026-3074 is an authorization bypass vulnerability that allows unauthorized access to sensitive information.