CVE-2026-6336: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing authorization check.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6336?
The severity of CVE-2026-6336 is medium with a CVSS score of 5.3.
How do I fix CVE-2026-6336?
To fix CVE-2026-6336, upgrade GitLab CE/EE to versions 19.0.5, 19.1.3, or 19.2.1 or later.
What type of vulnerability is CVE-2026-6336?
CVE-2026-6336 is classified as an Incorrect Authorization vulnerability.
Which versions of GitLab are affected by CVE-2026-6336?
CVE-2026-6336 affects all GitLab CE/EE versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.
What can an attacker do with CVE-2026-6336?
An attacker could potentially view project import source information due to a missing authorization check.