Improper access control in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-4672
Published: July 29, 2026 / Updated: July 30, 2026
GitLab Enterprise Edition
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote user to access test report contents they are not authorized to view.
The vulnerability exists due to improper access control enforcement in the Pipeline Test Report API when handling API requests. A remote user can send a request to access test report contents they are not authorized to view.
The issue affects users with guest-role permissions under certain conditions.