GitLab CE/EE Private Group Member Enumeration Vulnerability

Vulnerability

A vulnerability allowing authenticated users with project membership to enumerate private group members has been identified in GitLab CE/EE. This issue affects all versions from 15.1 prior to 18.9.7, 18.10 prior to 18.10.6, and 18.11 prior to 18.11.3. The vulnerability arises from insufficient authorization checks, which could have been exploited to access private group member information.

Impact

Exploitation of this vulnerability could lead to unauthorized enumeration of private group members, potentially allowing users to gain insights into private group dynamics and member roles.

Remediation

Users can upgrade to GitLab versions 18.11.3, 18.10.6, or 18.9.7 to address this vulnerability.

Added: May 14, 2026, 6:40 AM
Updated: May 14, 2026, 6:40 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
5.2
remediation
7.7
relevance
8.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.