CVE-2026-6269: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.10.8 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.11.5 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6269?
The severity of CVE-2026-6269 is classified as medium with a score of 5.4.
How do I fix CVE-2026-6269?
To fix CVE-2026-6269, upgrade GitLab to versions 18.10.8, 18.11.5, 19.0.2 or above.
What is the main issue reported in CVE-2026-6269?
CVE-2026-6269 describes an incorrect authorization issue in GitLab that could allow users with developer-role permissions to modify hidden merge requests.
Which versions of GitLab are affected by CVE-2026-6269?
CVE-2026-6269 affects GitLab CE/EE versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
Who is vulnerable to the CVE-2026-6269 exploit?
Authenticated users with developer-role permissions in affected versions of GitLab are vulnerable to the exploit described in CVE-2026-6269.