Incorrect authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-11379

 

Incorrect authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-11379

Published: June 25, 2026


Vulnerability identifier: #VU135177
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-11379
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose DAST site profile secrets.

The vulnerability exists due to incorrect authorization in dast scanner and site profile management when managing DAST site profiles. A remote user can access affected profile management functionality to disclose DAST site profile secrets.

The issue affects DAST site profile management.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition

How to mitigate CVE-2026-11379

Install security update from vendor's website.

GitLab Enterprise Edition - addressed in versions 18.11.6, 19.0.3, 19.1.1
Gitlab Community Edition - addressed in versions 18.11.6, 19.0.3, 19.1.1

External References

Related Security Bulletins