GitLab CE/EE Unauthenticated Organization Join Vulnerability

Vulnerability

A vulnerability exists in GitLab CE/EE versions 18.3 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1. Under certain conditions, this vulnerability could allow an unauthenticated user to join arbitrary organizations by modifying headers on specific requests.

Impact

Exploitation of this vulnerability could lead to unauthorized access to organizations within GitLab, allowing users to join organizations they do not belong to.

Added: Nov 26, 2025, 8:23 PM
Updated: Nov 26, 2025, 8:23 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
7.4
remediation
0.0
relevance
1.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.