GitLab EE Improper Authorization Vulnerability Allowing Access to Sensitive Deployment Data

Vulnerability

A vulnerability exists in GitLab EE versions 11.5 prior to 18.10.7, 18.11 prior to 18.11.4, and 19.0 prior to 19.0.1. Under certain conditions, this vulnerability could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects. The issue arises from improper authorization checks.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive deployment data on projects.

Added: May 28, 2026, 3:43 AM
Updated: May 28, 2026, 3:43 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
5.2
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.