CVE-2026-4363: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of authorization decisions.
Other sources
GitLab has remediated an issue that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of authorization decisions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-4363?
CVE-2026-4363 is classified as a high severity vulnerability due to incorrect authorization issues that could lead to unauthorized access.
How do I fix CVE-2026-4363?
To fix CVE-2026-4363, upgrade GitLab EE to version 18.10.1 or later, or to versions 18.9.4 or later, or 18.8.8 or later.
Which versions of GitLab EE are affected by CVE-2026-4363?
The affected versions of GitLab EE include versions from 18.1 up to 18.8.7, from 18.9 up to 18.9.3, and 18.10.1.
What type of vulnerability is CVE-2026-4363?
CVE-2026-4363 is an incorrect authorization vulnerability related to authorization caching.
Can an unauthenticated user exploit CVE-2026-4363?
No, CVE-2026-4363 requires an authenticated user to potentially gain unauthorized access due to improper caching.