Incorrect authorization in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-82837

 

Incorrect authorization in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-82837

Published: September 11, 2026


Vulnerability identifier: #VU149015
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-82837
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access sensitive credentials and tokens.

The vulnerability exists due to improper authorization checks in Workhorse senddata emitters when accessing internal data emission endpoints. A remote attacker can access internal data emission endpoints to obtain sensitive credentials and tokens.

The credentials and tokens can be obtained without transiting the expected proxy.


Affected software

Gitlab Community Edition
GitLab Enterprise Edition

How to mitigate CVE-2026-82837

Install security update from vendor's website.

Gitlab Community Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2
GitLab Enterprise Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2

External References

Related Security Bulletins