CVE-2026-3607: Access Control Check Implemented After Asset is Accessed in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access control.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3607?
CVE-2026-3607 has a medium severity level due to potential access control vulnerabilities.
How do I fix CVE-2026-3607?
To mitigate CVE-2026-3607, upgrade your GitLab CE or EE versions to 18.9.7, 18.10.6, or 18.11.3 or later.
Who is affected by CVE-2026-3607?
CVE-2026-3607 affects users of GitLab CE and EE from version 18.3 up to but not including 18.9.7, 18.10 up to but not including 18.10.6, and 18.11 up to but not including 18.11.3.
What does CVE-2026-3607 exploit?
CVE-2026-3607 exploits an access control check which is implemented after an asset has already been accessed, allowing potential privilege escalation.
Is there a workaround for CVE-2026-3607?
There is no official workaround for CVE-2026-3607; updating to a patched version is the recommended solution.