Missing Authorization in GitLab Enterprise Edition - CVE-2026-4879
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose external status check configuration restricted to higher-privileged roles.
The vulnerability exists due to improper access control in external status check API when handling requests to a merge request API endpoint. A remote user can send a crafted request to disclose external status check configuration restricted to higher-privileged roles.
The issue affects users with developer-role permissions.