CVE-2026-9807: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.10.7 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.11.4 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9807?
CVE-2026-9807 has a medium severity rating of 4.3.
How do I fix CVE-2026-9807?
To remediate CVE-2026-9807, upgrade to GitLab versions 18.10.7, 18.11.4, 19.0.1 or above.
What software does CVE-2026-9807 affect?
CVE-2026-9807 affects GitLab CE/EE versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1.
What is the nature of the vulnerability in CVE-2026-9807?
CVE-2026-9807 involves incorrect authorization that could allow blocked Project Access Tokens to access private resources.
When was CVE-2026-9807 published?
CVE-2026-9807 was published on May 28, 2026.