CVE-2026-5309: Authorization Bypass Through User-Controlled Key in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.11.6 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.0.3 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5309?
The severity of CVE-2026-5309 is classified as medium with a score of 5.4.
How do I fix CVE-2026-5309?
To fix CVE-2026-5309, upgrade to GitLab EE versions 18.11.6, 19.0.3, or 19.1.1 or later.
What is the nature of the vulnerability in CVE-2026-5309?
CVE-2026-5309 is an authorization bypass that allows an authenticated user to read or modify another group's virtual registry cleanup policy settings.
Which versions of GitLab are affected by CVE-2026-5309?
CVE-2026-5309 affects all GitLab EE versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1.
Can CVE-2026-5309 be exploited by unauthenticated users?
No, CVE-2026-5309 requires authentication for exploitation.