GitLab CE/EE Improper Authorization Vulnerability Allowing Unauthorized Access to Confidential Issue Content

Vulnerability

A vulnerability exists in GitLab CE/EE versions 18.9.1 prior to 18.9.7, 18.10 prior to 18.10.6, and 18.11 prior to 18.11.3. This vulnerability could have allowed an authenticated user to access confidential issue content in public projects without proper authorization, due to inadequate authorization checks.

Impact

Exploitation of this vulnerability could lead to unauthorized access to confidential issue content in public projects.

Added: May 14, 2026, 6:49 AM
Updated: May 14, 2026, 6:49 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
6.6
remediation
7.7
relevance
8.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.