CVE-2026-7514: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to improper authorization checks in the Generic Package Registry.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.1.8 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.2.6 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.3.2
Event History
Frequently Asked Questions
Which users and deployments are exposed?
GitLab CE/EE instances running versions from 13.9 up to, but excluding, 19.1.8; 19.2.6; or 19.3.2 are affected. Exploitation requires an authenticated user with Developer-role permissions.
What could an attacker do?
A Developer-role user could substitute Generic Package Registry package file content and hide packages from their owners. The provided impact assessment indicates integrity impact, with no stated confidentiality or availability impact.
Which upgrades remediate the issue?
Upgrade to 19.1.8, 19.2.6, or 19.3.2, as applicable to the release line in use.