Improper Authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-7492

 

Improper Authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-7492

Published: July 8, 2026


Vulnerability identifier: #VU137127
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-7492
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to determine the existence of a private project.

The vulnerability exists due to improper authorization controls in commit discussion display when accessing cross-project reference pages. A remote user can access crafted cross-project reference pages to determine the existence of a private project.

The advisory text describes the actor as unauthenticated, but the attacker label follows the provided CVSS vector.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition

How to mitigate CVE-2026-7492

Install security update from vendor's website.

GitLab Enterprise Edition - addressed in versions 18.11.7, 19.0.4, 19.1.2
Gitlab Community Edition - addressed in versions 18.11.7, 19.0.4, 19.1.2

External References

Related Security Bulletins