CVE-2026-4868: Authorization Bypass Through User-Controlled Key in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4868?
CVE-2026-4868 has a severity rating of 8.2, indicating high risk.
How do I fix CVE-2026-4868?
To remediate CVE-2026-4868, upgrade to GitLab versions 18.10.7, 18.11.4, or 19.0.1 and above.
What products are affected by CVE-2026-4868?
CVE-2026-4868 affects all versions of GitLab EE from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1.
What type of vulnerability is CVE-2026-4868?
CVE-2026-4868 is an authorization bypass vulnerability caused by improper user-controlled key handling in GitLab.
Could CVE-2026-4868 lead to data compromise?
Yes, CVE-2026-4868 could allow an authenticated user to run workflows under another user's identity, potentially leading to data compromise.