CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.

unknownCVE-2026-4672CVE-2026-12436CVE-2026-16553CVE-2026-13113CVE-2026-6267CVE-2026-15975
GitLab Inc. has fixed multiple vulnerabilities in GitLab, specifically in versions prior to 19.0.5, 19.1.3, and 19.2.1, including GitLab Enterprise Edition (EE) versions within these ranges. The vulnerabilities concern various components of GitLab: - Incorrect access control allowing authenticated users with guest rights to view test reports that should have been restricted. - Insufficient validation of user input allowing authenticated users to modify the CI/CD pipeline schemas of other users. - Incorrect handling of upstream requests in virtual registries leading to potential unauthorized information leaks. - A race condition that allowed bypassing the mandatory approval workflow and directly merging code into protected branches. - Insufficient access control in internal request processing allowing developers access to information outside their authorization. - Insufficient resource throttling when processing merge request discussions, which could be exploited by unauthenticated users for a denial-of-service. - Incorrect authorization controls on merge request collaboration allowing developers to continue committing after their access was revoked. - Incorrect authorization allowing unauthenticated users to view the titles of confidential issues via public merge requests. - Incorrect handling of untrusted content in the AI-assisted code review feature, potentially exposing project information. - Insufficient input sanitization allowing cross-site scripting (XSS) attacks via specially crafted URLs. - Incorrect authorization during token generation allowing authenticated users to bypass admin-governance policies. - Incorrect API access control allowing users with Maintainer role to modify protected branch settings. - Missing authorization control allowing unauthorized users access to information.

CSIRTS triage

What
Multiple vulnerabilities allow unauthorized access and modification of resources by authenticated users with insufficient permissions.
Who is affected
Authenticated users with guest rights in GitLab versions prior to 19.0.5, 19.1.3, and 19.2.1 are affected.
Urgency
Remediation is necessary as these vulnerabilities could lead to unauthorized access and data exposure, though they are not currently exploited.
Action
Users should upgrade to GitLab versions 19.0.5, 19.1.3, or 19.2.1 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch GitLab

Get an email when a new GitLab advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-30
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0270

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-4672coverage & exploitation statusNVD · CVE.org
CVE-2026-12436coverage & exploitation statusNVD · CVE.org
CVE-2026-16553coverage & exploitation statusNVD · CVE.org
CVE-2026-13113coverage & exploitation statusNVD · CVE.org
CVE-2026-6267coverage & exploitation statusNVD · CVE.org
CVE-2026-15975coverage & exploitation statusNVD · CVE.org
CVE-2025-14562coverage & exploitation statusNVD · CVE.org
CVE-2026-14351coverage & exploitation statusNVD · CVE.org
CVE-2026-15077coverage & exploitation statusNVD · CVE.org
CVE-2026-3093coverage & exploitation statusNVD · CVE.org
CVE-2026-15831coverage & exploitation statusNVD · CVE.org
CVE-2026-14341coverage & exploitation statusNVD · CVE.org
CVE-2026-6336coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for GitLab by GitLab

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories