Improper Authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-7492
Published: July 8, 2026
Vulnerability details
The vulnerability allows a remote user to determine the existence of a private project.
The vulnerability exists due to improper authorization controls in commit discussion display when accessing cross-project reference pages. A remote user can access crafted cross-project reference pages to determine the existence of a private project.
The advisory text describes the actor as unauthenticated, but the attacker label follows the provided CVSS vector.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-7492
Gitlab Community Edition - addressed in versions 18.11.7, 19.0.4, 19.1.2