NCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.
GitLab Inc. has fixed multiple vulnerabilities in GitLab, specifically in versions prior to 19.0.5, 19.1.3, and 19.2.1, including GitLab Enterprise Edition (EE) versions within these ranges. The vulnerabilities concern various components of GitLab: - Incorrect access control allowing authenticated users with guest rights to view test reports that should have been restricted. - Insufficient validation of user input allowing authenticated users to modify the CI/CD pipeline schemas of other users. - Incorrect handling of upstream requests in virtual registries leading to potential unauthorized information leaks. - A race condition that allowed bypassing the mandatory approval workflow and directly merging code into protected branches. - Insufficient access control in internal request processing allowing developers access to information outside their authorization. - Insufficient resource throttling when processing merge request discussions, which could be exploited by unauthenticated users for a denial-of-service. - Incorrect authorization controls on merge request collaboration allowing developers to continue committing after their access was revoked. - Incorrect authorization allowing unauthenticated users to view the titles of confidential issues via public merge requests. - Incorrect handling of untrusted content in the AI-assisted code review feature, potentially exposing project information. - Insufficient input sanitization allowing cross-site scripting (XSS) attacks via specially crafted URLs. - Incorrect authorization during token generation allowing authenticated users to bypass admin-governance policies. - Incorrect API access control allowing users with Maintainer role to modify protected branch settings. - Missing authorization control allowing unauthorized users access to information.
CSIRTS triage
- What
- Multiple vulnerabilities allow unauthorized access and modification of resources by authenticated users with insufficient permissions.
- Who is affected
- Authenticated users with guest rights in GitLab versions prior to 19.0.5, 19.1.3, and 19.2.1 are affected.
- Urgency
- Remediation is necessary as these vulnerabilities could lead to unauthorized access and data exposure, though they are not currently exploited.
- Action
- Users should upgrade to GitLab versions 19.0.5, 19.1.3, or 19.2.1 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GitLab
Get an email when a new GitLab advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0270
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-46720.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-124360.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-165530.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-131130.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-62670.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-159750.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2025-145620.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-143510.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-150770.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-30930.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-4672 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12436 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16553 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13113 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6267 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15975 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-14562 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14351 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15077 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3093 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15831 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14341 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6336 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] GitLab: Multiple vulnerabilitiescert-bund
- unknownGitLab Multiple Vulnerabilitieshkcert
- unknownMultiple Vulnerabilities in GitLab (July 30, 2026)cert-fr-avis
- mediumCVE-2026-6336: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, …nvd
- highCVE-2026-6267: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5…nvd
- mediumCVE-2026-4672: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, …nvd
- mediumCVE-2026-3093: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, …nvd
- mediumCVE-2026-16553: GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19…nvd
- highCVE-2026-15975: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5,…nvd
- mediumCVE-2026-15831: GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and…nvd
- mediumCVE-2026-15077: GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and…nvd
- mediumCVE-2026-14351: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, …nvd
Recent advisories for GitLab by GitLab
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownGitLab security advisory (AV26-758)cccs · 2026-07-30
- high[NEW] [high] GitLab: Multiple vulnerabilitiescert-bund · 2026-07-30
- unknownGitLab Multiple Vulnerabilitieshkcert · 2026-07-30
- unknownMultiple Vulnerabilities in GitLab (July 30, 2026)cert-fr-avis · 2026-07-30
- mediumCVE-2026-6336: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, …nvd · 2026-07-29
- highCVE-2026-6267: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5…nvd · 2026-07-29
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0269 [1.01] [M/H] Vulnerabilities fixed in VMware products2026-07-29