Back to overview

CVE-2026-3176

LOW
3.1
CVSS 3.1
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization checks.

Metadata

CVE ID
CVE-2026-3176
State
PUBLISHED
Assigner
GitLab
Reserved
2026-02-25 00:06 UTC
Published
2026-06-25 04:34 UTC
Last updated
2026-06-25 04:34 UTC
Primary CWE
CWE-862
CWE-862: Missing Authorization
Vendor / Product
GitLab / GitLab
Sources
cve.org  ·  NVD

Severity & Metrics

3.1 LOW CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
GitLab GitLab 18.6 < 18.11.6, 19.0 < 19.0.3, 19.1 < 19.1.1
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862: Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
3.1 LOW 3.1 cna CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Back to overview