AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18433

MEDIUM · CVSS 4.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

GitLab versions prior to 19.1.4 and 19.2.2 contain a vulnerability that allows authenticated users to access unauthorized policy configurations within a namespace, stemming from improper authorization checks in a GraphQL query. This could lead to sensitive information exposure, potentially impacting user privacy and security. Organizations using affected GitLab versions should prioritize applying the necessary updates to mitigate this risk.

CVE
CVE-2026-18433
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query.