Improper access control in GitLab Enterprise Edition - CVE-2026-10518
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to read private security policy content they are not authorized to access.
The vulnerability exists due to improper authorization enforcement in the GraphQL memberRoles dependentSecurityPolicies resolver when resolving security policies. A remote user can query the resolver to read private security policy content they are not authorized to access.
Exploitation requires guest-level permissions.