AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-6821

MEDIUM · CVSS 4.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

GitLab versions prior to 19.0.6, 19.1.4, and 19.2.2 are vulnerable to an authorization bypass that could allow authenticated users to access limited merge request information from private projects. This vulnerability arises from insufficient access controls in the merge requests API endpoint, potentially exposing sensitive data. Organizations using affected GitLab versions should prioritize remediation to safeguard their private project information.

CVE
CVE-2026-6821
Severity
MEDIUM
CVSS
4.3
EPSS
0.28%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint.