CVE-2026-8030: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to prevent another user from modifying their group settings due to improper validation of group URL slugs during namespace transfers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.3.2
Event History
Frequently Asked Questions
Which GitLab versions need remediation?
GitLab CE/EE is affected from version 13.0 up to, but not including, 19.1.8; 19.2.0 through 19.2.5; and 19.3.0 through 19.3.1. The remediated versions are 19.1.8, 19.2.6, and 19.3.2.
What access does an attacker need?
An attacker must be an authenticated GitLab user. The issue can be triggered under certain conditions involving improper validation of group URL slugs during namespace transfers.
What is the practical impact?
A successful attack could prevent another user from modifying their group settings, causing a limited availability impact. The provided severity vector indicates no confidentiality or integrity impact.