Missing Authorization in GitLab Enterprise Edition - CVE-2026-16494
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to modify project settings restricted to higher-privileged roles.
The vulnerability exists due to improper access control in ProjectsController when handling project update requests. A remote user can send a crafted project update request to modify project settings restricted to higher-privileged roles.