OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-4523

LOW · CVSS 3.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-05

CyberRota Analysis

AI-Generated

GitLab CE/EE versions prior to 19.2.7, 19.3.3, and 19.4.1 are vulnerable to improper authorization enforcement in the GraphQL API, potentially allowing unauthenticated users to access sensitive CI/CD job trace information. While the severity is rated low, organizations using affected versions should prioritize remediation to protect sensitive data from unauthorized access. Users managing CI/CD pipelines in GitLab should take immediate action to update their installations.

CVE
CVE-2026-4523
Severity
LOW
CVSS
3.7
EPSS
0.34%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.

Related CVEs

Other vulnerabilities affecting the same vendor(s)