CVE-2026-2726

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge requests in other projects due to improper access control during cross-repository operations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*

History

26 Mar 2026, 18:30

Type Values Removed Values Added
First Time Gitlab
Gitlab gitlab
Summary
  • (es) GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.10 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3, y la 18.10 anterior a la 18.10.1 que podría haber permitido a un usuario autenticado realizar acciones no autorizadas en solicitudes de fusión en otros proyectos debido a un control de acceso inadecuado durante operaciones entre repositorios.
References () https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/ - () https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/ - Release Notes, Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/work_items/590717 - () https://gitlab.com/gitlab-org/gitlab/-/work_items/590717 - Broken Link
References () https://hackerone.com/reports/3543886 - () https://hackerone.com/reports/3543886 - Permissions Required
CPE cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*

25 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 17:16

Updated : 2026-03-26 18:30


NVD link : CVE-2026-2726

Mitre link : CVE-2026-2726

CVE.ORG link : CVE-2026-2726


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-863

Incorrect Authorization