CVE-2026-1663

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the group import process under certain circumstances.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

17 Jun 2026, 10:16

Type Values Removed Values Added
Summary
  • (es) GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 14.4 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6 y la 18.9 anterior a la 18.9.2 que podría haber permitido a un usuario autenticado con permisos de importación de grupo crear etiquetas en proyectos privados debido a una validación de autorización incorrecta en el proceso de importación de grupo bajo ciertas circunstancias.

13 Mar 2026, 13:24

Type Values Removed Values Added
First Time Gitlab
Gitlab gitlab
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
References () https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/ - () https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/ - Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/work_items/588207 - () https://gitlab.com/gitlab-org/gitlab/-/work_items/588207 - Broken Link
References () https://hackerone.com/reports/3485548 - () https://hackerone.com/reports/3485548 - Permissions Required

11 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 16:16

Updated : 2026-06-17 10:16


NVD link : CVE-2026-1663

Mitre link : CVE-2026-1663

CVE.ORG link : CVE-2026-1663


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-862

Missing Authorization