Improper Authorization in GitLab Enterprise Edition - CVE-2026-18433
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose policy configuration belonging to an unauthorized namespace.
The vulnerability exists due to improper access control in AI Tool Rules GraphQL resolver when processing a GraphQL query. A remote user can send a crafted GraphQL query to disclose policy configuration belonging to an unauthorized namespace.