CVE-2026-5952: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package metadata due to incorrect authorization checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.11.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5952?
The severity of CVE-2026-5952 is medium with a score of 4.3.
How do I fix CVE-2026-5952?
To fix CVE-2026-5952, upgrade GitLab to version 18.11.6 or 19.0.3 or later.
What software is affected by CVE-2026-5952?
CVE-2026-5952 affects GitLab CE and GitLab EE versions released before 18.11.6, 19.0.3, and 19.1.1.
What type of vulnerability is CVE-2026-5952?
CVE-2026-5952 is an incorrect authorization vulnerability.
What can attackers do with CVE-2026-5952?
Attackers with developer-role permissions could bypass package protection rules and overwrite protected packages under certain conditions.