Incorrect authorization in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-82837
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to access sensitive credentials and tokens.
The vulnerability exists due to improper authorization checks in Workhorse senddata emitters when accessing internal data emission endpoints. A remote attacker can access internal data emission endpoints to obtain sensitive credentials and tokens.
The credentials and tokens can be obtained without transiting the expected proxy.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-82837
GitLab Enterprise Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2