CVE-2026-4523: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.2.7 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.3.3 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.4.1
Event History
Frequently Asked Questions
Which GitLab versions need remediation?
GitLab CE/EE is affected from 15.11 up to, but not including, 19.2.7; 19.3 versions before 19.3.3; and 19.4 versions before 19.4.1. Upgrade to 19.2.7, 19.3.3, 19.4.1, or a later release in the applicable release line.
What could an unauthenticated attacker access?
Under certain conditions, an unauthenticated user could read CI/CD job trace contents through the GraphQL API. The exposed traces may contain sensitive variable values.
Does exploitation require an account or user interaction?
No. The reported issue could be exploited by an unauthenticated user and does not require user interaction, although exploitation has high attack complexity and occurs only under certain conditions.