AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-8667

MEDIUM · CVSS 4.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

GitLab versions from 17.6 to 19.0.6, 19.1 to 19.1.4, and 19.2 to 19.2.2 are vulnerable to improper authorization checks, allowing authenticated users with developer roles to modify package registry metadata without appropriate maintainer permissions. This could lead to unauthorized changes in package integrity, potentially impacting the security and reliability of software deployments. Organizations using affected versions should prioritize applying the latest updates to mitigate this risk.

CVE
CVE-2026-8667
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks.