Improper Authentication in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-4363
Published: March 25, 2026 / Updated: March 26, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to resources.
The vulnerability exists due to improper caching of authorization decisions in authorization caching when handling requests under certain conditions. A remote user can send a specially crafted request to exploit stale or incorrect authorization cache entries and gain unauthorized access to resources.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-4363
Gitlab Community Edition - addressed in versions 18.8.7, 18.9.3, 18.10.1