CVE-2026-6976: Authorization Bypass Through User-Controlled Key in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.10.8 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.11.5 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6976?
CVE-2026-6976 has a low severity rating of 3.7.
How do I fix CVE-2026-6976?
To remediate CVE-2026-6976, upgrade to GitLab versions 18.10.8, 18.11.5, or 19.0.2 and above.
What software is affected by CVE-2026-6976?
CVE-2026-6976 affects GitLab CE and GitLab EE versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
What type of vulnerability is CVE-2026-6976?
CVE-2026-6976 is an authorization bypass vulnerability that allows certain users to hide changes in merge requests.
When was CVE-2026-6976 published?
CVE-2026-6976 was published on June 11, 2026.