Missing Authorization in GitLab Enterprise Edition - CVE-2026-6821
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose limited merge request information from a private project.
The vulnerability exists due to improper access control in merge requests API when handling requests to a merge requests endpoint. A remote user can send a crafted request to disclose limited merge request information from a private project.
The issue can bypass IP-based access restrictions.