CVE-2026-13151

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to modify group-level settings beyond their intended permissions due to improper authorization controls.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

09 Jul 2026, 20:34

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
First Time Gitlab
Gitlab gitlab
References () https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/ - () https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/ - Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/work_items/598813 - () https://gitlab.com/gitlab-org/gitlab/-/work_items/598813 - Broken Link

08 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 21:16

Updated : 2026-07-09 20:34


NVD link : CVE-2026-13151

Mitre link : CVE-2026-13151

CVE.ORG link : CVE-2026-13151


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-863

Incorrect Authorization