CVE-2026-5296: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level, could have allowed an authenticated user with developer-role permissions to bypass flow restrictions under certain conditions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5296?
The severity of CVE-2026-5296 is medium, with a score of 4.3.
How do I fix CVE-2026-5296?
To fix CVE-2026-5296, upgrade to GitLab versions 18.10.7, 18.11.4, 19.0.1 or above.
What impact does CVE-2026-5296 have on GitLab?
CVE-2026-5296 allows an authenticated user with developer-role permissions to bypass flow restrictions under certain conditions.
Which versions of GitLab are affected by CVE-2026-5296?
CVE-2026-5296 affects GitLab EE versions 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1.
What are the foundational flows mentioned in CVE-2026-5296?
The foundational flows refer to the flow restrictions implemented at the group level in GitLab that can be bypassed due to this vulnerability.