Incorrect authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-11379
Published: June 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose DAST site profile secrets.
The vulnerability exists due to incorrect authorization in dast scanner and site profile management when managing DAST site profiles. A remote user can access affected profile management functionality to disclose DAST site profile secrets.
The issue affects DAST site profile management.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-11379
Gitlab Community Edition - addressed in versions 18.11.6, 19.0.3, 19.1.1