Incorrect authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-11379
Published: June 25, 2026
GitLab Enterprise Edition
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote user to disclose DAST site profile secrets.
The vulnerability exists due to incorrect authorization in dast scanner and site profile management when managing DAST site profiles. A remote user can access affected profile management functionality to disclose DAST site profile secrets.
The issue affects DAST site profile management.