GitLab CE/EE Guest Permission Vulnerability Allowing Unauthorized Issue Access

Vulnerability

A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) in all versions from 15.1 prior to 18.9.7, 18.10 prior to 18.10.6, and 18.11 prior to 18.11.3. This vulnerability could have allowed an authenticated user with Guest permissions to view issues in projects they were not authorized to access.

Impact

Exploitation of this vulnerability could lead to unauthorized access to project issues, allowing users to view sensitive information they should not have access to.

Added: May 14, 2026, 6:57 AM
Updated: May 14, 2026, 6:57 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
6.6
remediation
7.7
relevance
8.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.