CVE-2026-6883: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.9.7 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.10.6 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.11.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6883?
CVE-2026-6883 is classified as a moderate severity vulnerability due to missing authorization that could allow an authenticated user to bypass approval requirements.
How do I fix CVE-2026-6883?
To fix CVE-2026-6883, upgrade your GitLab GitLab Enterprise Edition to version 18.9.7 or later, 18.10.6 or later, or 18.11.3 or later.
What versions are affected by CVE-2026-6883?
CVE-2026-6883 affects GitLab EE versions from 15.7 up to but not including 18.9.7, 18.10 up to but not including 18.10.6, and 18.11 up to but not including 18.11.3.
Who can be affected by CVE-2026-6883?
Authenticated users in GitLab GitLab Enterprise Edition can be affected by CVE-2026-6883 as they may bypass merge request approval requirements.
What is the main issue with CVE-2026-6883?
The main issue with CVE-2026-6883 is the improper cleanup of orphaned permissions, leading to potential security lapses in merge request approvals.